CVE-2026-0396
Discovered by AISLEPUBLISHEDImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Description
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.
CVSS Base Scores
CVSS v3.1(Primary)
3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Version | Status |
|---|---|---|---|
| PowerDNS | DNSdist | 1.9.0 | affected |
| PowerDNS | DNSdist | 2.0.0 | — |
Credits
- Aisle Research(finder)