PowerDNS DNSdist DNS over HTTPS ACL Bypass Vulnerability

Vulnerability

An ACL bypass vulnerability has been identified in PowerDNS DNSdist versions 1.9.0 through 1.9.11 and 2.0.0 through 2.0.2. When the 'early_acl_drop' option is disabled on a DNS over HTTPS frontend using the nghttp2 provider, the ACL check is bypassed. This allows all clients to send DoH queries, regardless of the configured ACL. The vulnerability can be exploited by sending crafted DoH queries, taking advantage of the skipped ACL checks.

Impact

Exploiting this vulnerability can lead to unauthorized clients bypassing ACL restrictions and sending DoH queries, potentially causing disruptions or unauthorized access to services that rely on these ACLs.

Remediation

Users can upgrade to PowerDNS DNSdist versions 1.9.12 or 2.0.3, where this vulnerability has been patched. Alternatively, the 'early_acl_drop' option can be kept enabled, which is the default setting.

Added: Mar 31, 2026, 12:31 PM
Updated: Mar 31, 2026, 12:31 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
7.6
remediation
8.3
relevance
5.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.