Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-0396

Опубликовано: 31 мар. 2026
Источник: nvd
CVSS3: 3.1
CVSS3: 4.3
EPSS Низкий

Описание

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*
Версия от 1.9.0 (включая) до 1.9.12 (исключая)
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.0.3 (исключая)

EPSS

Процентиль: 3%
0.00136
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 3.1
ubuntu
5 месяцев назад

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

CVSS3: 3.1
debian
5 месяцев назад

An attacker might be able to inject HTML content into the internal web ...

CVSS3: 4.3
redos
19 дней назад

Уязвимость dnsdist

CVSS3: 4.3
redos
19 дней назад

Уязвимость dnsdist

CVSS3: 3.1
github
5 месяцев назад

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

EPSS

Процентиль: 3%
0.00136
Низкий

3.1 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-80