Improper Encoding or Escaping of Output in dnsdist - CVE-2026-40011
Published: June 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass monitoring integrity.
The vulnerability exists due to improper output neutralization in the prometheus endpoint when processing crafted DNS queries that trigger dynamic block insertion via dynBlockRulesGroup():setSuffixMatchRule() or dynBlockRulesGroup():setSuffixMatchRuleFFI(). A remote attacker can send a large number of crafted DNS queries to bypass monitoring integrity.
The invalid output causes the prometheus endpoint to be rejected by the scraper until the dynamic block expires.
Affected software
Debian Linux
dnsdist (Debian package)
How to mitigate CVE-2026-40011
dnsdist (Debian package) - update to 1.9.15-0+deb13u1