VYPR

rpm package

opensuse/dnsdist&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Tumbleweed

Vulnerabilities (27)

  • CVE-2026-42004LowJun 25, 2026
    affected < 2.0.7-1.1fixed 2.0.7-1.1

    An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

  • CVE-2026-40211MedJun 25, 2026
    affected < 2.0.7-1.1fixed 2.0.7-1.1

    An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigg

  • CVE-2026-40210MedJun 25, 2026
    affected < 2.0.7-1.1fixed 2.0.7-1.1

    An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.

  • CVE-2026-40209MedJun 25, 2026
    affected < 2.0.7-1.1fixed 2.0.7-1.1

    An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to

  • CVE-2026-40208LowJun 25, 2026
    affected < 2.0.7-1.1fixed 2.0.7-1.1

    An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

  • CVE-2026-40011LowJun 25, 2026
    affected < 2.0.7-1.1fixed 2.0.7-1.1

    An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block ex

  • CVE-2026-42005MedJun 25, 2026
    affected < 2.0.7-1.1fixed 2.0.7-1.1

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

  • CVE-2026-33602MedApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service.

  • CVE-2026-33599LowApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default.

  • CVE-2026-33598MedApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.

  • CVE-2026-33597LowApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    PRSD detection denial of service

  • CVE-2026-33596LowApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend.

  • CVE-2026-33595MedApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection.

  • CVE-2026-33594MedApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection.

  • CVE-2026-33593HigApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.

  • CVE-2026-33254MedApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default.

  • CVE-2026-33260MedApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

  • CVE-2026-33257MedApr 22, 2026
    affected < 2.0.5-1.1fixed 2.0.5-1.1

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

  • CVE-2026-27854MedMar 31, 2026
    affected < 2.0.3-1.1fixed 2.0.3-1.1

    An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of the DNS packet that has been modified, thus trigg

  • CVE-2026-24030MedMar 31, 2026
    affected < 2.0.3-1.1fixed 2.0.3-1.1

    An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connectio

Page 1 of 2