Home
LOW: 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:NDefault status
unaffected
1.9.0 (semver) before 1.9.12
affected
2.0.0 (semver) before 2.0.3
affected
Description
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.
Problem types
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Product status
1.9.0 (semver) before 1.9.12
2.0.0 (semver) before 2.0.3
Credits
Aisle Research
References
www.dnsdist.org/...owerdns-advisory-for-dnsdist-2026-02.html