Dnsdist
Vendor:
First CVE: Aug 22, 2017 · Active for 8 years
29
Total CVEs
More Total CVEs than 97% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dnsdist over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2017
8 years ago
Most Recent CVE
Jun 25, 2026
33 days ago
CVE Severity & Scoring
Dnsdist29 CVEs
14%
28%
55%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (93.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (6.9%)
Attack Complexity
Low23 (79.3%)
High6 (20.7%)
Unknown0 (0.0%)
User Interaction
None26 (89.7%)
Unknown0 (0.0%)
Required3 (10.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None29 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24028HIGH An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of- | Mar 31, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-27853HIGH An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in cust | Mar 31, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-24030HIGH An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups w | Mar 31, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-27854HIGH An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQ | Mar 31, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-33598CRITICAL A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache. | Apr 22, 2026 | 9.1 | 29 | NO | NO |
CVE-2026-33602HIGH A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service | Apr 22, 2026 | 8.2 | 26 | NO | NO |
CVE-2026-33599HIGH A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade | Apr 22, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-33593HIGH A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query. | Apr 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-33257HIGH An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by defaul | Apr 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-30194HIGH When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (dou | Apr 29, 2025 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (29 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (29 CVEs).
Media Mentions
Signals from CVEs in this product scope (29 CVEs).
Top CNAs Publishing CVEs For Dnsdist
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.1.0 | 1 | 8.8 | 0.8% | 0 | 0 |