Junglewise Threat Intelligence

CVE-2026-42004: PowerDNS DNSdist EDNS options smuggling in EDNS processing

CVE-2026-42004 · Severity: low · CVSS 3.7 · Published 2026-06-25

Technologies: Powerdns Dnsdist. Vendors: Powerdns.

Executive brief

PowerDNS DNSdist is a load balancer used to manage and route internet traffic for DNS servers. A vulnerability exists where a specially crafted request can bypass security filtering rules when certain features are enabled. This could allow an attacker to 'smuggle' unauthorized data through the load balancer to internal backend servers, potentially bypassing intended security policies.

Technical details

A vulnerability in DNSdist's EDNS processing allows for 'EDNS options smuggling.' An attacker can send a malformed EDNS OPT record that is ignored by DNSdist's initial filtering rules. However, when DNSdist performs EDNS Client Subnet (ECS) insertion, it rewrites the record into a valid format. This causes backend servers to receive and process EDNS options that were intended to be blocked or filtered by the load balancer. The issue affects versions 1.9.x (up to 1.9.14) and 2.0.x (up to 2.0.6). Users are advised to upgrade to versions 1.9.15 or 2.0.7, or disable ECS insertion as a workaround.

Affected products

  • PowerDNS DNSdist 1.9.0 to 1.9.14, 2.0.0 to 2.0.6

Timeline

  • 2026-04-24: other: Discovery date
  • 2026-06-25: disclosed: Advisory published by PowerDNS
  • 2026-06-25: patched: Fixed in versions 1.9.15 and 2.0.7

References

Related threats