PT-2026-29241 · Powerdns · Dnsdist

Aisle Research

·

Publicado

2026-01-01

·

Atualizado

2026-04-24

·

CVE-2026-0396

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions DNSdist (affected versions not specified)
Description An attacker may be able to inject HTML content into the internal web dashboard by sending specially crafted DNS queries to a DNSdist instance. This is possible when domain-based dynamic rules are enabled using either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI. The attack involves manipulating DNS queries to achieve HTML injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-0396
OPENSUSE-SU-2026:10473-1
SUSE-SU-2026:1618-1

Produtos afetados

Dnsdist