← Vulnerability feed

Vulnerability record · CVE-2026-24028 · published 31 March 2026

CVE-2026-24028: Powerdns dnsdist vulnerability

Powerdns · Dnsdist

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure.

8.2 CVSS 3.1 High EPSS 1.0% · top 37.8% CWE-126 · CWE-126
8.2CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
25 Jul 2026Last modified by NVD

Description

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-24028 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-33598Powerdns dnsdist out-of-bounds read vulnerabilityA cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet c…EPSS 2.8%8.8CVE-2017-7557Powerdns dnsdist improper authentication vulnerabilitydnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.EPSS 0.83%8.2CVE-2026-33602Powerdns dnsdist heap-based buffer overflow vulnerabilityA rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write…EPSS 1.2%8.1CVE-2026-33599Powerdns dnsdist out-of-bounds read vulnerabilityA rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) opti…EPSS 0.80%7.5CVE-2026-33597Powerdns dnsdist vulnerabilityPRSD detection denial of serviceEPSS 0.75%7.5CVE-2026-33254Powerdns dnsdist allocation without limits vulnerabilityAn attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial o…EPSS 0.80%7.5CVE-2026-33593Powerdns dnsdist divide by zero vulnerabilityA client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.EPSS 0.82%7.5CVE-2026-33594Powerdns dnsdist allocation without limits vulnerabilityA client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accu…EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2026-24028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.