CVE-2026-0396 PUBLISHED

HTML injection in the web dashboard

Assigner: OX
Reserved: 28.11.2025 Published: 31.03.2026 Updated: 31.03.2026

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS Score: 3.1

Product Status

Vendor PowerDNS
Product DNSdist
Versions Default: unaffected
  • affected from 1.9.0 to 1.9.12 (excl.)
  • affected from 2.0.0 to 2.0.3 (excl.)

Credits

  • Aisle Research finder

References

Problem Types

  • Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) CWE