Low severity3.7NVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026
CVE-2026-42004
CVE-2026-42004
Description
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/dnsdist&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2016.0
< 2.0.7-1.1+ 1 more
- (no CPE)range: < 2.0.7-1.1
- (no CPE)range: < 1.9.15-160000.1.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.