PowerDNS DNSdist Internal Web Server Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in PowerDNS DNSdist versions through 2.0.3 and 1.9.12. The issue arises from the internal web server, which is disabled by default but can be activated. When the web server is enabled, an attacker can send crafted HTTP requests that cause unlimited memory allocation, leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability causes excessive memory consumption, which can lead to a denial-of-service condition by causing the application to become unresponsive or to crash.

Remediation

Users can upgrade to PowerDNS DNSdist versions 1.9.13 or 2.0.4, where this vulnerability has been patched. Alternatively, the internal web server can be disabled or restricted to trusted clients.

Added: Apr 22, 2026, 11:22 AM
Updated: Apr 22, 2026, 11:22 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
6.8
remediation
7.9
relevance
6.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.