A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service.Creditsylwango613Referenceshttps://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-04.html