Dnsdist

Vendor:

First CVE: Aug 22, 2017 · Active for 8 years

29
Total CVEs
More Total CVEs than 97% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Dnsdist over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2017
8 years ago
Most Recent CVE
Jun 25, 2026
33 days ago

CVE Severity & Scoring

Dnsdist29 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (93.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (6.9%)
Attack Complexity
Low23 (79.3%)
High6 (20.7%)
Unknown0 (0.0%)
User Interaction
None26 (89.7%)
Unknown0 (0.0%)
Required3 (10.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None29 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-
Mar 31, 20268.235NONO
An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in cust
Mar 31, 20267.533NONO
An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups w
Mar 31, 20267.533NONO
An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQ
Mar 31, 20267.532NONO
A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.
Apr 22, 20269.129NONO
A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service
Apr 22, 20268.226NONO
A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade
Apr 22, 20268.126NONO
A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.
Apr 22, 20267.526NONO
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by defaul
Apr 22, 20267.526NONO
When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (dou
Apr 29, 20257.526NONO

Exploit Exposure

Signals from CVEs in this product scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (29 CVEs).

Media Mentions

Signals from CVEs in this product scope (29 CVEs).

Top CNAs Publishing CVEs For Dnsdist

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.1.018.80.8%00