Junglewise Threat Intelligence

CVE-2026-0396: PowerDNS DNSdist HTML injection in web dashboard

CVE-2026-0396 · Severity: low · CVSS 3.1 · Published 2026-03-31

Technologies: Powerdns Dnsdist. Vendors: Powerdns.

Executive brief

PowerDNS DNSdist is a load balancer used to manage and route internet traffic for domain name services. A vulnerability in its management dashboard allows an attacker to inject malicious content into the administrative interface by sending specifically crafted network requests. If an administrator views the compromised dashboard, it could lead to unauthorized actions or the display of misleading information, though it does not directly grant full control over the server.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the PowerDNS DNSdist web dashboard due to improper neutralization of HTML tags (CWE-80). The issue is triggered when domain-based dynamic rules are enabled via 'DynBlockRulesGroup:setSuffixMatchRule' or 'DynBlockRulesGroup:setSuffixMatchRuleFFI'. An attacker can send crafted DNS queries that, when processed and displayed in the dashboard, inject arbitrary HTML. Exploitation requires the internal webserver to be enabled (it is disabled by default) and requires an administrator to interact with the dashboard. The vulnerability is fixed in versions 1.9.12 and 2.0.3.

Affected products

  • PowerDNS DNSdist 1.9.0 to 1.9.11, 2.0.0 to 2.0.2

Timeline

  • 2025-12-19: disclosed: Vulnerability discovered by Aisle Research
  • 2026-03-31: advisory: PowerDNS Security Advisory 2026-02 published
  • 2026-03-31: patched

References

Related threats