← Retour aux CVEs
CVE-2026-24029
MEDIUM6.5
Description
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.
Details CVE
Score CVSS v3.16.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie3/31/2026
Derniere modification4/1/2026
Sourcenvd
Observations honeypot0
Faiblesses (CWE)
CWE-863
References
https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html(security@open-xchange.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.