CVE-2026-40209
MEDIUM
5.3
CVSS 3.1
Description
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.
Metadata
Severity & Metrics
5.3
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| PowerDNS | DNSdist | — | 1.9.0 < 1.9.15, 2.0.0 < 2.0.7 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Missing Release of Resource after Effective Lifetime |
| CWE-772 | adp | CWE-772 Missing Release of Resource after Effective Lifetime |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.3 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
References (1)