CVE-2026-40011
EUVD-2026-3934625.06.2026, 13:16
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| powerdns | dnsdist | 1.9.0 ≤ 𝑥 < 1.9.15 | CNA |
| powerdns | dnsdist | 2.0.0 ≤ 𝑥 < 2.0.7 | CNA |
Debian Releases