CVE-2026-40209
Deferred
Deferred - Pending Action
IXFR Query Induced TCP Connection Leak in Open-Xchange
Publication date: 2026-06-25
Last updated on: 2026-06-25
Assigner: Open-Xchange
Description
Description
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| powerdns | dnsdist | to 2.0.6 (inc) |
| powerdns | dnsdist | to 1.9.14 (inc) |
| powerdns | dnsdist | From 1.9.15 (inc) |
| powerdns | dnsdist | From 2.0.7 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-772 | The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed. |