CVE-2026-24030Patch(powerdns / dnsdist)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch powerdns dnsdist systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connection is properly closed, but in some cases the system might enter an out-of-memory state instead and terminate the process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dnsdist

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-31); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
dnsdist

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-31: 1Mentions · 2026-04-10: 1Mentions · 2026-04-14: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-14: 103-3104-1004-14
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-311
Disclosure1
2026-04-101
Patch1
2026-04-141
Patch1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #DNS admins: A single crafted QUIC packet can crash your load balancer (CVE-2026-24030). Patch or mitigate now. Here’s the 60-second iptables fix → https://tinyurl.com/47b2f936 #Fedora https://t.co/sakTcPl1z0

    Post summary

    The tweet alerts DNS admins that CVE‑2026‑24030 allows a crafted QUIC packet to crash load balancers and urges immediate patching or a 60‑second iptables fix, which is linked in the post.

    00010133
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24030 An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of servic… https://www.cve.org/CVERecord?id=CVE-2026-24030

    Post summary

    The CVE details a memory allocation flaw in DNSdist that could cause a denial of service when handling DNS over QUIC or HTTP/3, but no PoC, exploit, patch, or active exploitation evidence is provided.

    00010116
    56.9K followersView on X
  • DNSAudit.io@dnsaudit
    Patch

    🚨 CVE-2026-24030: DNSdist DoS via QUIC/HTTP3 https://www.sentinelone.com/vulnerability-database/cve-2026-24030/ A flaw in DNSdist lets attackers exhaust memory by sending crafted DNS over QUIC or HTTP/3 requests. No auth needed. Under load or low memory, it can trigger OOM and crash the service, disrupting DNS resolution. If you’re running DoQ or DoH3, patch now or consider disabling them temporarily. Monitor memory spikes, restarts, and unusual QUIC/HTTP3 traffic patterns. #DNS #DNSSecurity #CyberSecurity #InfoSec #Vulnerability

    Post summary

    CVE‑2026‑24030 is a DNSdist denial‑of‑service flaw via QUIC/HTTP3 that can cause OOM crashes; administrators should apply patches or disable DoQ/DoH3 to mitigate.

    0000037
    13 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppowerdnsdnsdist---

Explore more