CVE-2025-30187

Source
https://cve.org/CVERecord?id=CVE-2025-30187
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-30187.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-30187
Downstream
Related
Published
2025-09-18T09:21:32.274Z
Modified
2026-07-11T03:54:18.421397464Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Denial of service via crafted DoH exchange in PowerDNS DNSdist
Details

In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.

Database specific
{
    "cwe_ids": [
        "CWE-835"
    ],
    "cna_assigner": "OX",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30187.json"
}
References

Affected packages

Git / github.com/powerdns/pdns

Affected ranges

Type
GIT
Repo
https://github.com/powerdns/pdns
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "1.9.0"
        },
        {
            "fixed": "1.9.11"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.0.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

dnsdist-1.*
dnsdist-1.9.0
dnsdist-1.9.1
dnsdist-1.9.10
dnsdist-1.9.2
dnsdist-1.9.3
dnsdist-1.9.4
dnsdist-1.9.5
dnsdist-1.9.6
dnsdist-1.9.7
dnsdist-1.9.8
dnsdist-1.9.9
dnsdist-2.*
dnsdist-2.0.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-30187.json"