Security Advisory

CVE-2026-40011

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-25 12:22:19
Last updated 2026-06-25 13:23:46
Assigner OX
CVSS score 3.7
State PUBLISHED

Description

An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.