CVE-2026-40011
Prometheus denial of service via crafted DNS queries
Description
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.
INFO
Published Date :
June 25, 2026, 12:22 p.m.
Last Modified :
June 25, 2026, 12:22 p.m.
Remotely Exploit :
Yes !
Source :
OX
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | LOW | 8ce71d90-2354-404b-a86e-bec2cc4e6981 | ||||
| CVSS 3.1 | LOW | [email protected] |
Solution
- Filter crafted DNS queries that trigger invalid output.
- Validate dynamic block insertion values.
- Monitor and alert on endpoint rejections.
- Update system to handle dynamic blocks gracefully.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-40011 vulnerability anywhere in the article.