Overly permissive cross-domain whitelist in dnsdist - CVE-2026-0397
Published: April 23, 2026
dnsdist
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose information about the running configuration from the dashboard.
The vulnerability exists due to a cross-origin resource sharing policy misconfiguration in the internal webserver dashboard when an administrator logged to the dashboard visits a malicious website. A remote attacker can trick the administrator into visiting a malicious website to disclose information about the running configuration from the dashboard.
The issue is present only when the internal webserver is enabled.