3.7
LOW CVSS 3.1
CVE-2026-40011
Prometheus denial of service via crafted DNS queries
Description

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.

INFO

Published Date :

June 25, 2026, 12:22 p.m.

Last Modified :

June 25, 2026, 12:22 p.m.

Remotely Exploit :

Yes !

Source :

OX
Affected Products

The following products are affected by CVE-2026-40011 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Powerdns dnsdist
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 LOW 8ce71d90-2354-404b-a86e-bec2cc4e6981
CVSS 3.1 LOW [email protected]
Solution
Prevent DoS by filtering crafted DNS queries and validating dynamic block data.
  • Filter crafted DNS queries that trigger invalid output.
  • Validate dynamic block insertion values.
  • Monitor and alert on endpoint rejections.
  • Update system to handle dynamic blocks gracefully.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-40011 vulnerability anywhere in the article.

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.