Incorrect authorization in dnsdist - CVE-2026-24029
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass access controls for DNS over HTTPS queries.
The vulnerability exists due to improper access control in the DNS over HTTPS frontend using the nghttp2 provider when the early_acl_drop option is disabled. A remote attacker can send DoH queries to bypass access controls for DNS over HTTPS queries.
The issue occurs only on DNS over HTTPS frontends using the nghttp2 provider with early_acl_drop disabled.
Affected software
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
Basesystem Module
dnsdist
dnsdist-debugsource
dnsdist-debuginfo
dnsdist (Debian package)
How to mitigate CVE-2026-24029
dnsdist - addressed in versions 1.9.12-1.el8, 1.9.12-1.el9, 1.9.12-1.fc42, 2.0.3-1.el10_3, 2.0.3-1.fc43, 2.0.3-1.fc44
dnsdist-debugsource - update to 1.9.12-150700.3.9.1
dnsdist-debuginfo - update to 1.9.12-150700.3.9.1
dnsdist - update to 1.9.12-150700.3.9.1
dnsdist (Debian package) - update to 1.9.14-0+deb13u1