← back
CVE-2025-30187lowCWE-835

Denial of service via crafted DoH exchange in PowerDNS DNSdist

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.7epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected products
PowerDNS · DNSdist