CVE-2026-0397

Source
https://cve.org/CVERecord?id=CVE-2026-0397
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-0397.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-0397
Downstream
Related
Published
2026-03-31T11:53:13.444Z
Modified
2026-05-18T05:59:42.063908464Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Information disclosure via CORS misconfiguration
Details

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin Resource Sharing (CORS) policy.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0397.json",
    "cna_assigner": "OX"
}
References

Affected packages

Git / github.com/powerdns/pdns

Affected ranges

Type
GIT
Repo
https://github.com/powerdns/pdns
Events

Affected versions

dnsdist-2.*
dnsdist-2.0.0
dnsdist-2.0.1
dnsdist-2.0.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-0397.json"