Executive brief
PowerDNS DNSdist is a load balancer used to manage and route DNS traffic. A security flaw in its optional web dashboard could allow an attacker to trick an administrator into visiting a malicious website, which then silently extracts configuration details from the dashboard. This could expose sensitive operational information about the network's DNS infrastructure.
Technical details
A misconfiguration of the Cross-Origin Resource Sharing (CORS) policy in the DNSdist internal webserver allows for information disclosure. If the internal webserver is enabled (it is disabled by default), an attacker can perform a cross-origin attack by tricking an authenticated administrator into visiting a malicious website. This allows the attacker's site to make requests to the DNSdist dashboard and extract the running configuration. The vulnerability affects versions 1.9.0 through 1.9.11 and 2.0.0 through 2.0.2. It is fixed in versions 1.9.12 and 2.0.3. Users can also mitigate the risk by disabling the internal webserver.
Affected products
- PowerDNS DNSdist 1.9.0 to 1.9.11, 2.0.0 to 2.0.2
Timeline
- 2026-01-13: disclosed: Discovery date reported by vendor
- 2026-03-31: advisory: Vendor advisory and CVE published
- 2026-03-31: patched: Fixed versions 1.9.12 and 2.0.3 released