Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-3871

34
FAUCET Score

CVE-2019-3871 describes an insufficient data validation vulnerability in PowerDNS Authoritative Server versions prior to 4.0.7 and 4.1.7, specifically within the HTTP Connector of the Remote backend. This flaw allows an authenticated remote attacker to craft DNS queries that manipulate HTTP requests, potentially leading to a denial of service by directing the server to an invalid endpoint or enabling information disclosure by connecting to internal endpoints. Rated with a CVSS score of 8.8 (High), the vulnerability has a low attack complexity and can result in high impact to confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.0.7CPE matchmatch criteria
cpe:2.3:a:powerdns:authoritative_server:*:*:*:*:*:*:*:*
>= 4.1.0, < 4.1.7CPE matchmatch criteria
cpe:2.3:a:powerdns:authoritative_server:*:*:*:*:*:*:*:*
28CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
29CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.5MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.0

Exploit Intelligence

EPSS Score
12.63%
Probability of exploitation in next 30 days
EPSS Percentile
95.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1263 is in the 95th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia nvd_reference
View patch

References

lists.opensuse.org / opensuse-security-announce/2019-04/msg00022.html
bugzilla.redhat.com / show_bug.cgi
ExploitIssue TrackingPatchThird Party Advisory
doc.powerdns.com / authoritative/security-advisories/powerdns-advisory-2019-03.html
Vendor Advisory
lists.debian.org / debian-lts-announce/2019/03/msg00039.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GWUHF6MRSQ3YO7UUISGLV7MXCAGBW2VD
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ROFI6OTWF4GKONNSNEDUCW6LVSSEBZNF
seclists.org / bugtraq/2019/Apr/8
debian.org / security/2019/dsa-4424
openwall.com / lists/oss-security/2019/03/18/4
ExploitMailing ListPatchThird Party Advisory
securityfocus.com / bid/107491
Third Party AdvisoryVDB Entry