CVE Explorer
CVE-2026-40011
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7f8f401af6ab2da8d49bdfcf07af823cad43a94f886ed09a44f5870f478e076d · sha256:28c6915cf4bc695e… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-116","description":"CWE-116 Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7f8f401af6ab2da8d49bdfcf07af823cad43a94f886ed09a44f5870f478e076d · sha256:28c6915cf4bc695e… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"collectionURL":"https://repo.powerdns.com/","defaultStatus":"unaffected","modules":["Prometheus export"],"packageName":"dnsdist","product":"DNSdist","programFiles":["dnsdist-web.cc"],"repo":"https://github.com/PowerDNS/pdns","vendor":"PowerDNS","versions":[{"lessThan":"1.9.15","status":"affected","version":"1.9.0","versionType":"semver"},{"lessThan":"2.0.7","status":"affected","version":"2.0.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7f8f401af6ab2da8d49bdfcf07af823cad43a94f886ed09a44f5870f478e076d · sha256:28c6915cf4bc695e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7f8f401af6ab2da8d49bdfcf07af823cad43a94f886ed09a44f5870f478e076d · sha256:28c6915cf4bc695e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"description":"Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7f8f401af6ab2da8d49bdfcf07af823cad43a94f886ed09a44f5870f478e076d · sha256:28c6915cf4bc695e… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-116","description":"CWE-116 Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7f8f401af6ab2da8d49bdfcf07af823cad43a94f886ed09a44f5870f478e076d · sha256:28c6915cf4bc695e… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-09.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7f8f401af6ab2da8d49bdfcf07af823cad43a94f886ed09a44f5870f478e076d · sha256:28c6915cf4bc695e… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.