Incorrect authorization in dnsdist - CVE-2026-24029

 

Incorrect authorization in dnsdist - CVE-2026-24029

Published: April 23, 2026


Vulnerability identifier: #VU126957
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24029
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass access controls for DNS over HTTPS queries.

The vulnerability exists due to improper access control in the DNS over HTTPS frontend using the nghttp2 provider when the early_acl_drop option is disabled. A remote attacker can send DoH queries to bypass access controls for DNS over HTTPS queries.

The issue occurs only on DNS over HTTPS frontends using the nghttp2 provider with early_acl_drop disabled.


Affected software

dnsdist
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
Basesystem Module
dnsdist
dnsdist-debugsource
dnsdist-debuginfo
dnsdist (Debian package)

How to mitigate CVE-2026-24029

Install security update from vendor's website.

dnsdist - addressed in versions 1.9.12, 2.0.3
dnsdist - addressed in versions 1.9.12-1.el8, 1.9.12-1.el9, 1.9.12-1.fc42, 2.0.3-1.el10_3, 2.0.3-1.fc43, 2.0.3-1.fc44
dnsdist-debugsource - update to 1.9.12-150700.3.9.1
dnsdist-debuginfo - update to 1.9.12-150700.3.9.1
dnsdist - update to 1.9.12-150700.3.9.1
dnsdist (Debian package) - update to 1.9.14-0+deb13u1

External References

Related Security Bulletins