CVE-2026-40011
Last modified
CVE-2026-40011 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-40011?
How severe is CVE-2026-40011?
How do I fix CVE-2026-40011?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40006Memory Allocation with Excessive Size Value, Allocation of R…7.5
- CVE-2026-40007Uncontrolled Recursion, Uncontrolled Resource Consumption vu…7.5
- CVE-2026-40008Use of Externally-Controlled Input to Select Classes or Code…9.8
- CVE-2026-40009Improper Privilege Management, Improper Access Control vulne…6.5
- CVE-2026-4001The Woocommerce Custom Product Addons Pro plugin for WordPre…9.8
- CVE-2026-40010Missing invocation of Servlet http web request method change…9.1
- CVE-2026-40012ECS zero scoped answers are stored in the packet cache while…5.3
- CVE-2026-40013An attacker that has valid credentials can submit a Sieve sc…4.3
- CVE-2026-40014An attacker that can send mail to a user can craft a message…6.5
- CVE-2026-40015An attacker that has valid credentials can open many connect…4.3
- CVE-2026-40016Attacker can upload a malicious Sieve script over ManageSiev…6.5
- CVE-2026-40017An attacker that can send mail to a user can craft a message…6.5
Are you affected by CVE-2026-40011?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
