CVE-2026-24029

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/03/2026
Last modified:
14/04/2026

Description

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:* 1.9.0 (including) 1.9.12 (excluding)
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.3 (excluding)