CVE-2026-24028
PowerDNS DNSdist, dnsdist
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a denial of service, or access unrelated memory, leading to potential information disclosure.
- CVSS
- 8.2
- EPSS
- 1.03% 60.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.31