allocation in the internal web server, leading to a denial of service.
The internal web server is disabled by default.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6367-1 | dnsdist security update |
Debian DSA |
DSA-6368-1 | pdns security update |
Debian DSA |
DSA-6369-1 | pdns-recursor security update |
Fri, 26 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Powerdns
Powerdns authoritative |
|
| Vendors & Products |
Powerdns
Powerdns authoritative |
Thu, 25 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-368 |
Thu, 25 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
ssvc
|
Thu, 25 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-368 |
Thu, 25 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. | |
| Title | Insufficient input validation of internal web server | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-06-25T13:04:12.854Z
Reserved: 2026-04-23T11:15:21.199Z
Link: CVE-2026-42005
Updated: 2026-06-25T13:04:09.406Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T23:45:04Z
Debian DSA