CVE-2026-42004
LOW SEVERITYCVSS Score & Metrics
Base Score
3.7 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Description
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-115
Source
NVD
Vendor
PowerDNS
Product
DNSdist
Discussion (0)
Add Comment
No comments yet. Be the first!