Untriaged
Permalink
CVE-2026-24029
6.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): NONE
DNS over HTTPS ACL bypass
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.
Affected products
dnsdist
- <1.9.12
- <2.0.3
Package maintainers
-
@jojosch Johannes Schleifenbaum <johannes@js-webcoding.de>