CVE-2026-0396: Powerdns Dnsdist

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

Affected products

  • Powerdns Dnsdist: from 1.9.0, before 1.9.12 (fixed in 1.9.12); from 2.0.0, before 2.0.3 (fixed in 2.0.3)

Published 2026-03-31. Last modified 2026-07-25.