Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in dnsdist - CVE-2026-0396
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject HTML content into the internal web dashboard.
The vulnerability exists due to improper neutralization of input during web page generation in the internal web dashboard when processing crafted DNS queries triggering domain-based dynamic rules. A remote attacker can send crafted DNS queries to inject HTML content into the internal web dashboard.
User interaction is required for the injected content to be viewed, and the issue occurs when domain-based dynamic rules have been enabled via DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.
Affected software
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
Basesystem Module
dnsdist
dnsdist-debugsource
dnsdist-debuginfo
dnsdist (Debian package)
How to mitigate CVE-2026-0396
dnsdist - addressed in versions 1.9.12-1.el8, 1.9.12-1.el9, 1.9.12-1.fc42, 2.0.3-1.el10_3, 2.0.3-1.fc43, 2.0.3-1.fc44
dnsdist-debugsource - update to 1.9.12-150700.3.9.1
dnsdist-debuginfo - update to 1.9.12-150700.3.9.1
dnsdist - update to 1.9.12-150700.3.9.1
dnsdist (Debian package) - update to 1.9.14-0+deb13u1