An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.
References
Configurations
No configuration.
History
25 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-116 |
25 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-25 13:16
Updated : 2026-06-25 16:00
NVD link : CVE-2026-40011
Mitre link : CVE-2026-40011
CVE.ORG link : CVE-2026-40011
JSON object : View
Products Affected
No product.
CWE
CWE-116
Improper Encoding or Escaping of Output
