| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-42005 | vulnerable | vulnerable | fixed | vulnerable | vulnerable | An attacker can send a web request that causes unlimited memory alloc ... |
| CVE-2026-42004 | vulnerable | vulnerable | fixed | vulnerable | vulnerable | An attacker can send a crafted EDNS OPT record that will be ignored by ... |
| CVE-2026-40211 | vulnerable | vulnerable | fixed | vulnerable | vulnerable | An attacker can send crafted DNS over HTTP/3 queries, triggering an ex ... |
| CVE-2026-40210 | vulnerable | vulnerable | fixed | vulnerable | vulnerable | An out-of-bounds read might happen when SetMacAddrAction is used, pote ... |
| CVE-2026-40209 | vulnerable | vulnerable | fixed | vulnerable | vulnerable | An attacker might be able to cause outgoing TCP connections to backend ... |
| CVE-2026-40208 | vulnerable | vulnerable | fixed | vulnerable | vulnerable | An attacker might be able to delay the processing of DoH3 queries by s ... |
| CVE-2026-40011 | vulnerable | vulnerable | fixed | vulnerable | vulnerable | An attacker sending a large number of crafted DNS queries might be abl ... |
| CVE-2026-33602 | vulnerable | vulnerable | fixed | fixed | fixed | A rogue backend can send a crafted UDP response with a query ID off by ... |
| CVE-2026-33599 | vulnerable | vulnerable | fixed | fixed | fixed | A rogue backend can send a crafted SVCB response to a Discovery of Des ... |
| CVE-2026-33598 | vulnerable | vulnerable | fixed | fixed | fixed | A cached crafted response can cause an out-of-bounds read if custom Lu ... |
| CVE-2026-33597 | vulnerable | vulnerable | fixed | fixed | fixed | PRSD detection denial of service |
| CVE-2026-33596 | vulnerable | vulnerable | fixed | fixed | fixed | A client might theoretically be able to cause a mismatch between queri ... |
| CVE-2026-33595 | vulnerable | vulnerable | fixed | fixed | fixed | A client can trigger excessive memory allocation by generating a lot o ... |
| CVE-2026-33594 | vulnerable | vulnerable | fixed | fixed | fixed | A client can trigger excessive memory allocation by generating a lot o ... |
| CVE-2026-33593 | vulnerable | vulnerable | fixed | fixed | fixed | A client can trigger a divide by zero error leading to crash by sendin ... |
| CVE-2026-33260 | vulnerable | vulnerable | fixed | fixed | fixed | An attacker can send a web request that causes unlimited memory alloca ... |
| CVE-2026-33257 | vulnerable | vulnerable | fixed | fixed | fixed | An attacker can send a web request that causes unlimited memory alloca ... |
| CVE-2026-33254 | vulnerable | vulnerable | fixed | fixed | fixed | An attacker can create a large number of concurrent DoQ or DoH3 connec ... |
| CVE-2026-27854 | vulnerable | vulnerable | fixed | fixed | fixed | An attacker might be able to trigger a use-after-free by sending craft ... |
| CVE-2026-27853 | vulnerable | vulnerable | fixed | fixed | fixed | An attacker might be able to trigger an out-of-bounds write by sending ... |
| CVE-2026-24030 | vulnerable | vulnerable | fixed | fixed | fixed | An attacker might be able to trick DNSdist into allocating too much me ... |
| CVE-2026-24029 | vulnerable | vulnerable | fixed | fixed | fixed | When the early_acl_drop (earlyACLDrop in Lua) option is disabled (defa ... |
| CVE-2026-24028 | vulnerable | vulnerable | fixed | fixed | fixed | An attacker might be able to trigger an out-of-bounds read by sending ... |
| CVE-2026-0397 | vulnerable | vulnerable | fixed | fixed | fixed | When the internal webserver is enabled (default is disabled), an attac ... |
| CVE-2026-0396 | vulnerable | vulnerable | fixed | fixed | fixed | An attacker might be able to inject HTML content into the internal web ... |
| CVE-2025-30193 | vulnerable | vulnerable | fixed | fixed | fixed | In some circumstances, when DNSdist is configured to allow an unlimite ... |
| CVE-2023-44487 | vulnerable (no DSA) | vulnerable | fixed | fixed | fixed | The HTTP/2 protocol allows a denial of service (server resource consum ... |