CVE-2025-30187 Details
Description
In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.
A denial-of-service vulnerability has been identified in PowerDNS DNSdist versions 1.9.0 prior to 1.9.10 and 2.0.0. When DNSdist is set to use the nghttp2 library for processing incoming DNS over HTTPS (DoH) queries, an attacker can exploit this vulnerability by creating a DoH exchange that triggers an unbounded input/output read loop. This exploitation leads to unexpected CPU resource consumption, causing a denial-of-service condition.
Users can upgrade to DNSdist versions 1.9.11 or 2.0.1, both of which include the necessary patch. Alternatively, DNSdist can be configured to use the h2o provider, which does not have this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2025CISA-ADP
Assessed Sep 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/09/18/1 | CVE | |
| https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2025-05.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PowerDNS DNSdist | >= 1.9.0, <= 1.9.10 (semver) 2.0.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Sep 18, 2025 | New CVE Received | [email protected] |
Volerion