Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-35517 — Detection scripts for Pi-hole FTLDNS RCE (CVE-2026-35517) via newline injection, including Python scanner and Nmap NSE script for version-based vulnerability assessment. | Kitploit
Tools/GitHubGitHub/keraattin/cve-2026-35517
Vulnerability ScannersExploitationInformation GatheringWeb SecurityNetwork SecurityPenetration Testing
GitHubkeraattin/cve-2026-35517

CVE-2026-35517

Detection scripts for Pi-hole FTLDNS RCE (CVE-2026-35517) via newline injection, including Python scanner and Nmap NSE script for version-based vulnerability assessment.

View Repository
185 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-35517 - Pi-hole FTLDNS Remote Code Execution via Newline Injection

CVE-2026-35517 CVSS 8.8 CWE-93 FTLDNS 6.0-6.5

TL;DR

A Remote Code Execution vulnerability in Pi-hole's FTLDNS engine (versions 6.0 through 6.5) allows an authenticated attacker to inject arbitrary dnsmasq configuration directives by embedding newline characters (\n) into the dns.upstreams API parameter. Since dnsmasq supports directives that execute shell commands, this newline injection directly translates to full command execution on the host system.

This isn't just a single bug, it's a class of injection that affects five different configuration parameters, all patched together in FTL v6.6.


Table of Contents

  • Quick Facts
  • What is Pi-hole FTLDNS?
  • Vulnerability Deep Dive
    • Understanding the Architecture
    • The Injection Point
    • From Newline to Shell — The Kill Chain
    • The Full Family — Five Injection Vectors
  • Impact Analysis
  • Affected Versions
  • Who is at Risk?
  • Detection
    • Python Scanner
    • Nmap NSE Script
    • Manual Version Check
  • Indicators of Compromise
  • Remediation
  • References
  • Author

Quick Facts

FieldDetail
CVE IDCVE-2026-35517
VendorPi-hole Project
ProductFTLDNS (pihole-FTL)
Affected Versions6.0 to < 6.6
CVSS v3.18.8 (High)
CWECWE-93 — Improper Neutralization of CRLF Sequences
Attack VectorNetwork
AuthenticationRequired (Pi-hole admin/API access)
User InteractionNone
PublishedApril 7, 2026
Patched InFTL v6.6 (released April 3, 2026)
Discovered ByT0X1Cx
Related AdvisoriesGHSA-23w8-7333-p9fj, GHSA-wxhv-w77q-6qwp, GHSA-28g5-gg88-wh5m, GHSA-fqv2-qhfh-ghcj, GHSA-vfmq-jrx3-wv3c

What is Pi-hole FTLDNS?

Pi-hole is one of the most widely deployed DNS sinkholes in the world. It sits on your network, handles DNS queries, and blocks ads and trackers at the DNS level before they ever reach your browser. It's used everywhere from single Raspberry Pi setups in apartments to enterprise deployments protecting thousands of devices.

FTLDNS (Faster Than Light DNS) is Pi-hole's core engine. It's a custom fork/wrapper around dnsmasq, the well-known DNS and DHCP server. FTLDNS handles:

  • DNS query resolution and caching
  • DNS-level blocking (the core Pi-hole function)
  • DHCP server functionality
  • Query logging and statistics
  • The API that the web interface talks to

Here's the key detail: FTLDNS generates dnsmasq configuration files from user-supplied settings through its API. If you change the upstream DNS server in the Pi-hole admin panel, FTLDNS writes that value into a dnsmasq configuration file and restarts the service. That write path is where the vulnerability lives.


Vulnerability Deep Dive

Understanding the Architecture

+------------------+            +------------------+               +------------------+
|   Admin Panel    |  API/Web   |  FTLDNS Engine   | Config Write  |    dnsmasq       |
|    (Web UI)      | ---------> |  (pihole-FTL)    | ------------> |   (DNS/DHCP)     |
+------------------+            +------------------+               +------------------+
                                        |                                   |
                                  Reads settings,                     Reads config,
                                  writes to config                    serves DNS/DHCP
                                  files on disk                       to network

When an admin changes the upstream DNS servers through the Pi-hole web UI or API, the flow is:

  1. The web UI sends a request to the FTLDNS API with the new upstream DNS value
  2. FTLDNS validates the input (or rather, fails to validate it properly)
  3. FTLDNS writes the value into a dnsmasq configuration directive
  4. dnsmasq is restarted and reads the new configuration

The Injection Point

The dns.upstreams parameter is intended to accept DNS server addresses like 8.8.8.8 or 1.1.1.1. FTLDNS writes these into the dnsmasq config as server= directives:

# Normal input: "8.8.8.8"
# Generates:
server=8.8.8.8

The problem: FTLDNS does not sanitize newline characters in the input. An attacker can inject \n to break out of the intended server= directive and inject entirely new configuration lines:

# Malicious input: "8.8.8.8\ndhcp-option=6,evil.dns.server"
# Generates:
server=8.8.8.8
dhcp-option=6,evil.dns.server

This alone would be concerning (DNS hijacking via DHCP option injection). But it gets worse.

From Newline to Shell — The Kill Chain

dnsmasq supports a configuration directive called dhcp-option that can reference external scripts, and more critically, it supports several directives that can execute commands in specific scenarios. The exploitation chain looks like this:

Step 1: Attacker authenticates to Pi-hole 
        (default creds, weak password, CSRF, compromised session)

Step 2: Attacker sends API request to update dns.upstreams:
        
        POST /api/dns/upstream
        {
          "upstreams": ["8.8.8.8\n<malicious dnsmasq directive>"]
        }

Step 3: FTLDNS writes the value to the dnsmasq config file 
        without sanitizing the newline

Step 4: The injected dnsmasq directive is parsed as a 
        legitimate configuration option

Step 5: Depending on the directive injected, the attacker achieves:
        - DNS hijacking (redirect all DNS queries)
        - DHCP poisoning (push malicious configs to clients)
        - Command execution via dnsmasq's scripting capabilities
        - File write to arbitrary paths

The key insight is that this isn't about exploiting a dnsmasq vulnerability, dnsmasq is working as designed. The vulnerability is that FTLDNS lets untrusted input bleed into the configuration file, turning a configuration management API into an arbitrary config injection point.

The Full Family — Five Injection Vectors

The researcher (T0X1Cx) discovered that the same newline injection pattern affects five different FTLDNS configuration parameters. This is a systemic issue — the code lacked input sanitization across the board:

AdvisoryParameterWhat It Controls
GHSA-23w8-7333-p9fjdns.upstreamsUpstream DNS servers
GHSA-wxhv-w77q-6qwpdns.hostRecordCustom DNS host records
GHSA-28g5-gg88-wh5mdns.cnameRecordsCNAME record mappings
GHSA-fqv2-qhfh-ghcjdhcp.leaseTimeDHCP lease duration
GHSA-vfmq-jrx3-wv3cdhcp.hostsStatic DHCP host assignments

Each of these parameters writes to dnsmasq configuration files, and each failed to sanitize newline characters. The fix in FTL v6.6 added proper input validation that rejects newline characters (and other control characters) across all configuration parameters.


Impact Analysis

Download Tool