Improper Input Validation in PowerDNS Affecting DNS Dist
CVE-2026-40011
3.7LOW
What is CVE-2026-40011?
A vulnerability in PowerDNS DNS Dist may allow an attacker to exploit the Prometheus endpoint by sending a flood of specially crafted DNS queries. This can result in the creation of a dynamic block, which may lead to the production of invalid outputs. Consequently, the Prometheus scraper will reject the endpoint until the dynamic block expires, potentially disrupting service and monitoring capabilities.
Affected Version(s)
DNSdist 1.9.0 < 1.9.15
DNSdist 2.0.0 < 2.0.7
