{"id":"CVE-2026-40211","summary":"Denial of service via crafted DoH3 queries","details":"An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition, resulting in a denial of service.","modified":"2026-08-14T18:51:43.695314793Z","published":"2026-06-25T12:23:55.585Z","related":["SUSE-SU-2026:23123-1","SUSE-SU-2026:23146-1","openSUSE-SU-2026:11411-1","openSUSE-SU-2026:21533-1"],"database_specific":{"cna_assigner":"OX","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40211.json"},"references":[{"type":"WEB","url":"https://repo.powerdns.com/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40211.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40211"},{"type":"ADVISORY","url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-09.html"},{"type":"PACKAGE","url":"https://github.com/PowerDNS/pdns"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powerdns/pdns","events":[{"introduced":"298a9d67fb760a12eabe89164f92fb814572aea8"},{"fixed":"3348a4f5e1ea95ed90ad6bbdf9c7f12be72e9bfc"},{"introduced":"89747e81bc60d7950276d5fda3ca669fa81b7cf9"},{"fixed":"5bd46a775a7d72376c6a22b2313173a187d439dd"}],"database_specific":{"extracted_events":[{"introduced":"1.9.0"},{"fixed":"1.9.15"},{"introduced":"2.0.0"},{"fixed":"2.0.7"}],"source":"AFFECTED_FIELD"}}],"versions":["dnsdist-1.9.14","dnsdist-2.0.6","dnsdist-2.0.5","dnsdist-2.0.2","dnsdist-2.0.1","dnsdist-1.9.11","dnsdist-2.0.0","dnsdist-1.9.10","dnsdist-1.9.9","dnsdist-1.9.8","dnsdist-1.9.7","dnsdist-1.9.6","dnsdist-1.9.5","dnsdist-1.9.4","dnsdist-1.9.3","dnsdist-1.9.2","dnsdist-1.9.1","dnsdist-1.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40211.json","vanir_signatures_modified":"2026-08-12T16:25:06Z","vanir_signatures":[{"id":"CVE-2026-40211-39fe2f8e","signature_type":"Function","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/3348a4f5e1ea95ed90ad6bbdf9c7f12be72e9bfc","target":{"file":"ext/yahttp/yahttp/reqresp.cpp","function":"feed"},"deprecated":false,"digest":{"function_hash":"175905571297022484819797437345790495302","length":6030}},{"target":{"file":"ext/yahttp/yahttp/reqresp.cpp"},"deprecated":false,"digest":{"line_hashes":["146073261330685155030523374299187221356","139999140489202660150035160998558678530","260398486233326308600521181399778936346","178066237530059398734757326132960946649"],"threshold":0.9},"id":"CVE-2026-40211-5ad4401b","signature_type":"Line","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/3348a4f5e1ea95ed90ad6bbdf9c7f12be72e9bfc"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/5bd46a775a7d72376c6a22b2313173a187d439dd","target":{"file":"ext/yahttp/yahttp/reqresp.cpp"},"deprecated":false,"digest":{"line_hashes":["146073261330685155030523374299187221356","139999140489202660150035160998558678530","260398486233326308600521181399778936346","178066237530059398734757326132960946649"],"threshold":0.9},"id":"CVE-2026-40211-8834b793"},{"source":"https://github.com/powerdns/pdns/commit/5bd46a775a7d72376c6a22b2313173a187d439dd","target":{"file":"ext/yahttp/yahttp/reqresp.cpp","function":"feed"},"deprecated":false,"digest":{"length":6074,"function_hash":"237403263111315157988973709551044007080"},"id":"CVE-2026-40211-f428faf8","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}