DNSdist是DNSdist开源的一款高度感知 DNS、DoS 和滥用的负载均衡器。 DNSdist存在安全漏洞,该漏洞源于启用内部Web服务器时,跨源资源共享策略配置不当,可能导致攻击者诱骗管理员访问恶意网站并从仪表板提取运行配置信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24029 | 6.5 MEDIUM | DNS over HTTPS ACL bypass |
| CVE-2026-27853 | 5.9 MEDIUM | Out-of-bounds write when rewriting large DNS packets |
| CVE-2026-24030 | 5.3 MEDIUM | Unbounded memory allocation for DoQ and DoH3 |
| CVE-2026-24028 | 5.3 MEDIUM | Out-of-bounds read when parsing DNS packets via Lua |
| CVE-2026-27854 | 4.8 MEDIUM | Use after free when parsing EDNS options in Lua |
| CVE-2026-0396 | 3.1 LOW | HTML injection in the web dashboard |
No comments yet