Improper Input Validation in PowerDNS Affecting DNS Dist
CVE-2026-40011

3.7LOW

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-40011?

A vulnerability in PowerDNS DNS Dist may allow an attacker to exploit the Prometheus endpoint by sending a flood of specially crafted DNS queries. This can result in the creation of a dynamic block, which may lead to the production of invalid outputs. Consequently, the Prometheus scraper will reject the endpoint until the dynamic block expires, potentially disrupting service and monitoring capabilities.

Affected Version(s)

DNSdist 1.9.0 < 1.9.15

DNSdist 2.0.0 < 2.0.7

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haruki Oyama (Waseda University)
.