CVE-2025-30187

Source
https://cve.org/CVERecord?id=CVE-2025-30187
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30187.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-30187
Downstream
Related
Published
2025-09-18T10:15:32Z
Modified
2026-03-16T03:08:39.718444Z
Summary
[none]
Details

In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.

References

Affected packages