Overly permissive cross-domain whitelist in dnsdist - CVE-2026-0397
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose information about the running configuration from the dashboard.
The vulnerability exists due to a cross-origin resource sharing policy misconfiguration in the internal webserver dashboard when an administrator logged to the dashboard visits a malicious website. A remote attacker can trick the administrator into visiting a malicious website to disclose information about the running configuration from the dashboard.
The issue is present only when the internal webserver is enabled.
Affected software
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Fedora
Basesystem Module
dnsdist
dnsdist-debugsource
dnsdist-debuginfo
dnsdist (Debian package)
How to mitigate CVE-2026-0397
dnsdist - addressed in versions 1.9.12-1.el8, 1.9.12-1.el9, 1.9.12-1.fc42, 2.0.3-1.el10_3, 2.0.3-1.fc43, 2.0.3-1.fc44
dnsdist-debugsource - update to 1.9.12-150700.3.9.1
dnsdist-debuginfo - update to 1.9.12-150700.3.9.1
dnsdist - update to 1.9.12-150700.3.9.1
dnsdist (Debian package) - update to 1.9.14-0+deb13u1