Unrated severityNVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026
EDNS options smuggling
CVE-2026-42004
Description
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.