Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40011

Опубликовано: 25 июн. 2026
Источник: debian

Описание

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsdistfixed2.1.0-1package
dnsdistend-of-lifebookwormpackage
dnsdistend-of-lifebullseyepackage

Примечания

  • https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-09.html#cve-2026-40011-prometheus-denial-of-service-via-crafted-dns-queries

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

CVSS3: 3.7
nvd
около 2 месяцев назад

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

CVSS3: 3.7
github
около 2 месяцев назад

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

suse-cvrf
13 дней назад

Security update for dnsdist