Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4qq-c3qm-82jj

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

EPSS

Процентиль: 5%
0.00156
Низкий

3.7 Low

CVSS3

Дефекты

CWE-115

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

CVSS3: 3.7
nvd
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

CVSS3: 3.7
debian
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by ...

suse-cvrf
11 дней назад

Security update for dnsdist

EPSS

Процентиль: 5%
0.00156
Низкий

3.7 Low

CVSS3

Дефекты

CWE-115