CVE-2026-40208 Details
Description
An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.
A denial-of-service vulnerability has been identified in PowerDNS DNSdist versions prior to 2.0.7 and 1.9.15. The issue arises when an attacker sends DoH3 GET queries containing an invalid DATA frame, potentially delaying the processing of these queries. This vulnerability can be exploited by sending a large number of such crafted DoH3 queries, causing an exception that prevents proper memory management. While the memory will eventually be freed at the end of the QUIC connection, the delay can be exploited to create an out-of-memory condition, leading to a denial-of-service situation.
Users are advised to upgrade to PowerDNS DNSdist versions 1.9.15 or 2.0.7, or to disable DNS over HTTP/3.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-09.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-705 | Incorrect Control Flow Scoping | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| PowerDNS DNSdist | <= 2.0.6 (semver) <= 1.9.14 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion