CVE-2026-40011 Details
Description
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.
A denial-of-service vulnerability has been identified in PowerDNS DNSdist versions through 2.0.6 and 1.9.14. The issue arises when an attacker sends a large number of crafted DNS queries, which can trigger the insertion of a dynamic block. This block can produce invalid output on the Prometheus endpoint, causing the endpoint to be rejected by the scraper until the block expires.
Users can upgrade to PowerDNS DNSdist versions 1.9.15 or 2.0.7, or avoid using the 'dynBlockRulesGroup():setSuffixMatchRule()' or 'dynBlockRulesGroup():setSuffixMatchRuleFFI()' functions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-09.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| PowerDNS DNSdist | <= 2.0.6 (semver) <= 1.9.14 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion