Overly permissive cross-domain whitelist in dnsdist - CVE-2026-0397

 

Overly permissive cross-domain whitelist in dnsdist - CVE-2026-0397

Published: April 23, 2026


Vulnerability identifier: #VU126955
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0397
CWE-ID: CWE-942
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose information about the running configuration from the dashboard.

The vulnerability exists due to a cross-origin resource sharing policy misconfiguration in the internal webserver dashboard when an administrator logged to the dashboard visits a malicious website. A remote attacker can trick the administrator into visiting a malicious website to disclose information about the running configuration from the dashboard.

The issue is present only when the internal webserver is enabled.


Affected software

dnsdist
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
Basesystem Module
dnsdist
dnsdist-debugsource
dnsdist-debuginfo
dnsdist (Debian package)

How to mitigate CVE-2026-0397

Install security update from vendor's website.

dnsdist - addressed in versions 1.9.12, 2.0.3
dnsdist - addressed in versions 1.9.12-1.el8, 1.9.12-1.el9, 1.9.12-1.fc42, 2.0.3-1.el10_3, 2.0.3-1.fc43, 2.0.3-1.fc44
dnsdist-debugsource - update to 1.9.12-150700.3.9.1
dnsdist-debuginfo - update to 1.9.12-150700.3.9.1
dnsdist - update to 1.9.12-150700.3.9.1
dnsdist (Debian package) - update to 1.9.14-0+deb13u1

External References

Related Security Bulletins