Highlights
Denial of Service: 62 prior fixes. Scrutinize any change in this area.
pdns/validate.cc: most-fixed (20 issues). Treat as high-risk during review.
156 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
DNSSEC Validation Bypass: Numerous fixes target DNSSEC denial-of-existence validation, especially NSEC/NSEC3 owner/signer/zone membership and wildcard proofs. Bypasses allow forging denial responses, leading to cache poisoning and incorrect DNS resolution.
Auth Bypass: Multiple endpoints and protocols (web API, webserver, dnsdist console, DNS updates, AXFR) have had authentication bypasses, often from missing checks on secondary paths, default-allow configurations, or broken validation logic.
Denial of Service: Resource exhaustion via connection/stream limits, oversized HTTP frames, and unbounded buffering is a dominant risk, particularly in DoH/DoQ and webserver components.