Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-42004

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

EPSS

Процентиль: 5%
0.00156
Низкий

3.7 Low

CVSS3

Дефекты

CWE-115

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

CVSS3: 3.7
debian
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by ...

CVSS3: 3.7
github
около 2 месяцев назад

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.

suse-cvrf
11 дней назад

Security update for dnsdist

EPSS

Процентиль: 5%
0.00156
Низкий

3.7 Low

CVSS3

Дефекты

CWE-115