Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f83r-q8f4-f336

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

EPSS

Процентиль: 5%
0.00153
Низкий

3.7 Low

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

CVSS3: 3.7
nvd
около 2 месяцев назад

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

CVSS3: 3.7
debian
около 2 месяцев назад

An attacker sending a large number of crafted DNS queries might be abl ...

suse-cvrf
13 дней назад

Security update for dnsdist

EPSS

Процентиль: 5%
0.00153
Низкий

3.7 Low

CVSS3

Дефекты

CWE-116