Pi-hole disclosed two high-severity remote code execution vulnerabilities in its FTLDNS component, tracked as CVE-2026-35518 and CVE-2026-35520, affecting pihole-FTL versions 6.0 through before 6.6. The flaws let an authenticated attacker inject arbitrary dnsmasq configuration directives through newline characters in the dns.cnameRecords and dhcp.leaseTime configuration parameters, which can result in command execution on the underlying system.
Both issues carry a CVSS v3.1 score vector of AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating low-complexity network exploitation with high impact to confidentiality, integrity, and availability once authenticated access is obtained. The vulnerabilities are mapped to CWE-78 and CWE-93, and Pi-hole fixed both in version 6.6; one related advisory is published as GHSA-28g5-gg88-wh5m.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Two CVE records were published for the Pi-hole FTL vulnerabilities, documenting the FTLDNS newline-injection RCE issues and linking them to GitHub security advisories. Both entries assigned high-severity CVSS 3.1 scores and mapped the flaws to CWE-78 and CWE-93.
Pi-hole addressed two authenticated remote code execution vulnerabilities in FTLDNS affecting versions 6.0 through before 6.6. The flaws involved improper handling of the dhcp.leaseTime and dns.cnameRecords configuration parameters, allowing newline injection of arbitrary dnsmasq directives and potential command execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.