CVE-2025-30187

EUVD-2025-30004
In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
OXCNA
3.7 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
powerdnsdnsdist
1.9.0 ≤
𝑥
< 1.9.11
CNA
powerdnsdnsdist
2.0.0 ≤
𝑥
< 2.0.1
CNA
Debian logo
Debian Releases
Debian Product
Codename
dnsdist
bookworm
1.7.3-2
fixed
bullseye
1.5.1-3
fixed
forky
2.0.3-1
fixed
sid
2.0.3-1
fixed
trixie
1.9.10-1+deb13u1
fixed