CVE-2026-40211

Source
https://cve.org/CVERecord?id=CVE-2026-40211
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40211.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-40211
Downstream
Related
Published
2026-06-25T12:23:55.585Z
Modified
2026-08-14T18:51:43.695314793Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Denial of service via crafted DoH3 queries
Details

An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition, resulting in a denial of service.

Database specific
{
    "cna_assigner": "OX",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40211.json"
}
References

Affected packages

Git / github.com/powerdns/pdns

Affected ranges

Type
GIT
Repo
https://github.com/powerdns/pdns
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.9.0"
        },
        {
            "fixed": "1.9.15"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.0.7"
        }
    ]
}

Affected versions

dnsdist-1.*
dnsdist-1.9.0
dnsdist-1.9.1
dnsdist-1.9.10
dnsdist-1.9.11
dnsdist-1.9.14
dnsdist-1.9.2
dnsdist-1.9.3
dnsdist-1.9.4
dnsdist-1.9.5
dnsdist-1.9.6
dnsdist-1.9.7
dnsdist-1.9.8
dnsdist-1.9.9
dnsdist-2.*
dnsdist-2.0.0
dnsdist-2.0.1
dnsdist-2.0.2
dnsdist-2.0.5
dnsdist-2.0.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40211.json"
vanir_signatures
[
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "175905571297022484819797437345790495302",
            "length": 6030.0
        },
        "target": {
            "function": "feed",
            "file": "ext/yahttp/yahttp/reqresp.cpp"
        },
        "source": "https://github.com/powerdns/pdns/commit/3348a4f5e1ea95ed90ad6bbdf9c7f12be72e9bfc",
        "signature_version": "v1",
        "id": "CVE-2026-40211-39fe2f8e",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "146073261330685155030523374299187221356",
                "139999140489202660150035160998558678530",
                "260398486233326308600521181399778936346",
                "178066237530059398734757326132960946649"
            ]
        },
        "target": {
            "file": "ext/yahttp/yahttp/reqresp.cpp"
        },
        "source": "https://github.com/powerdns/pdns/commit/3348a4f5e1ea95ed90ad6bbdf9c7f12be72e9bfc",
        "signature_version": "v1",
        "id": "CVE-2026-40211-5ad4401b",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "146073261330685155030523374299187221356",
                "139999140489202660150035160998558678530",
                "260398486233326308600521181399778936346",
                "178066237530059398734757326132960946649"
            ]
        },
        "target": {
            "file": "ext/yahttp/yahttp/reqresp.cpp"
        },
        "source": "https://github.com/powerdns/pdns/commit/5bd46a775a7d72376c6a22b2313173a187d439dd",
        "signature_version": "v1",
        "id": "CVE-2026-40211-8834b793",
        "deprecated": false
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "237403263111315157988973709551044007080",
            "length": 6074.0
        },
        "target": {
            "function": "feed",
            "file": "ext/yahttp/yahttp/reqresp.cpp"
        },
        "source": "https://github.com/powerdns/pdns/commit/5bd46a775a7d72376c6a22b2313173a187d439dd",
        "signature_version": "v1",
        "id": "CVE-2026-40211-f428faf8",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-08-12T16:25:06Z"