Impact
An attacker might delay the processing of DoH3 queries by sending DoH3 GET requests that contain an invalid DATA frame. The malformed frame causes the DNSdist server to wait, idling resources and leading to a degradation of service for legitimate traffic. The flaw does not provide a path to compromise confidentiality or integrity and is limited to availability impacts.
Affected Systems
The affected product is PowerDNS DNSdist. The advisory does not specify impacted versions, so all deployments of DNSdist that support DoH3 should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 3.7 indicates a low severity. EPSS data is not available, so the probability of automated exploitation is uncertain. The vulnerability is not listed in CISA KEV, implying no known widespread exploitation. The likely attack vector is network‑based through DoH3 over HTTPS, requiring the ability to send malformed DNS queries to the server. An adversary could flood the network with such queries to exhaust resources or simply disrupt service availability over time.
OpenCVE Enrichment