Low severity3.7NVD Advisory· Published Jun 25, 2026· Updated Jun 25, 2026
CVE-2026-40011
CVE-2026-40011
Description
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.
Affected products
2- osv-coords2 versionspkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Tumbleweed
< 1.9.15-160000.1.1+ 1 more
- (no CPE)range: < 1.9.15-160000.1.1
- (no CPE)range: < 2.0.7-1.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.