CVE-2026-40011: low-severity vulnerability in PowerDNS DNSdist
Prometheus denial of service via crafted DNS queries
Published
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.7epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
PowerDNS · DNSdistRelated CVEs — PowerDNS DNSdist
In the same product, most dangerous first.
CVE-2026-33598MEDIUMOut-of-bounds read in cache inspection via LuaEPSS 2.8%CVE-2025-30194HIGHDenial of service via crafted DoH exchangeEPSS 2.3%CVE-2026-27853MEDIUMOut-of-bounds write when rewriting large DNS packetsEPSS 1.5%CVE-2026-27854MEDIUMUse after free when parsing EDNS options in LuaEPSS 1.3%CVE-2026-33602MEDIUMOff-by-one access when processing crafted UDP responsesEPSS 1.2%CVE-2024-25581HIGHTransfer requests received over DoH can lead to a denial of service in DNSdistEPSS 1.1%