CVE-2026-42004 - EDNS options smuggling
CVE ID :CVE-2026-42004
Published : June 25, 2026, 12:24 p.m. | 1 hour, 17 minutes ago
Description :An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 25, 2026, 12:24 p.m. | 1 hour, 17 minutes ago
Description :An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...