CVE-2026-40209
EUVD-2026-3934825.06.2026, 13:16
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| powerdns | dnsdist | 1.9.0 ≤ 𝑥 < 1.9.15 | CNA |
| powerdns | dnsdist | 2.0.0 ≤ 𝑥 < 2.0.7 | CNA |
Debian Releases
Common Weakness Enumeration