CVE-2026-40011

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.
Configurations

No configuration.

History

25 Jun 2026, 14:16

Type Values Removed Values Added
CWE CWE-116

25 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-25 13:16

Updated : 2026-06-25 16:00


NVD link : CVE-2026-40011

Mitre link : CVE-2026-40011

CVE.ORG link : CVE-2026-40011


JSON object : View

Products Affected

No product.

CWE
CWE-116

Improper Encoding or Escaping of Output