CVE-2026-40011: invalid output produced in the prometheus endpoint when a large number of crafted DNS queries are sent
(bsc#1269204).
CVE-2026-40208: processing of DoH3 queries can be delayed via DoH3 GET queries with an invalid DATA frames
(bsc#1269207).
CVE-2026-40209: outgoing TCP connections to backend can get stuck until a timeout occurs when specially crafted IXFR
queries are sent (bsc#1269206).
CVE-2026-40210: out-of-bounds read when SetMacAddrAction is used can lead to uninitialized memory being sent over
the network or a crash (bsc#1269205).
CVE-2026-40211: crafted DNS over HTTP/3 queries can trigger an exception that prevents memory from being freed and can
lead to an OOM condition (bsc#1269203).
CVE-2026-42004: crafted EDNS OPT record will be ignored by filtering rules, but will be rewritten as a valid OPT
record when EDNS Client Subnet is inserted (bsc#1269202).
CVE-2026-42005: crafted web request can cause unlimited memory allocation in the internal web server and lead to a DoS
(bsc#1269201).