#VU115968 Resource exhaustion in dnsdist - CVE-2025-30187
Published: September 19, 2025
dnsdist
PowerDNS.COM B.V.
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources within the nghttp2 library when handling incoming DNS over HTTPS queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.