Related Threat Clusters
-
Critical Host Header Injection Vulnerability in Poweradmin (CVE-2026-54588)
A critical vulnerability identified as CVE-2026-54588 affects Poweradmin, a web-based DNS administration tool for PowerDNS server. The flaw allows unauthenticated attackers to exploit the HTTP_HOST request header to…
2 articles · Updated June 25, 2026 -
Critical Vulnerabilities in Fedora 43: Information Disclosure and Header Smuggling
Fedora 43 has reported two critical vulnerabilities affecting libsoup3 and perl-HTTP-Tiny. CVE-2026-5119, published on March 30, 2026, allows information disclosure via cleartext transmission of cookies during HTTPS…
99 articles · Updated June 5, 2026 -
Debian Trixie Vulnerabilities: PowerDNS and NSS Denial of Service Issues
Recent security advisories from Debian detail vulnerabilities in the Trixie stable distribution. The PowerDNS vulnerability (DSA-6284) allows for denial of service and information disclosure, fixed in version…
2 articles · Updated May 21, 2026 -
Spamhaus Launches Free and Commercial DNS Firewall Services
On June 15, 2026, Spamhaus announced the availability of both free and commercial DNS Firewall services. The free service offers access to DNS Response Policy Zones (RPZ) to block IPs associated with malicious…
2 articles · Updated June 15, 2026
Recent Intelligence Reports
- Fedora 43 pdns Update Security Advisory 2026 — Linuxsecurity · August 15, 2026
- CVE-2026-54588: Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. [CRITICAL] CVSS 9.6 Exploit Intelligence — Recent CVEs / 23h Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without any validation. An unauthe — exploit-intel.com · June 25, 2026
- DNS Response Policy Zones | Free (DNS Firewall) — www.spamhaus.com · June 15, 2026
- Debian Trixie PowerDNS Denial of Service Info Disclosure Vuln DSA-6284 — Linuxsecurity · May 20, 2026