{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pi-hole--5.18.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.5,"id":"CVE-2024-34361"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pi-hole (\u003c= 5.18.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","ssrf"],"_cs_type":"advisory","_cs_vendors":["Pi-hole"],"content_html":"\u003cp\u003eCVE-2024-34361 is a security vulnerability in the Pi-hole DNS sinkhole software affecting versions 5.18.2 and earlier. The flaw stems from improper validation of URL inputs, specifically within the authenticated admin login endpoint. An attacker who has gained low-level authenticated access to the Pi-hole administration interface can leverage this input validation weakness to trigger a Server-Side Request Forgery (SSRF). By manipulating the request body, an attacker can coerce the application to send requests to arbitrary internal services.\u003c/p\u003e\n\u003cp\u003eTechnical analysis indicates that this SSRF can be escalated to full Remote Code Execution (RCE) through the use of the Gopherus protocol, which allows the crafting of payloads for various services. Successful exploitation grants the attacker the ability to execute arbitrary commands on the underlying host, leading to a complete compromise of system integrity and availability. The availability of public exploit proof-of-concept (PoC) code significantly increases the risk of exploitation for organizations currently running unpatched instances of Pi-hole.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains low-level credentials to access the Pi-hole web-based administration interface.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the 'admin/login.php' endpoint and establishes an authenticated session.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a vulnerable input parameter in the request body that fails to properly sanitize URLs.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request payload incorporating the Gopherus protocol syntax to target internal services or local binaries.\u003c/li\u003e\n\u003cli\u003eThe Pi-hole server processes the malicious URL, triggering an outbound SSRF request to the specified target.\u003c/li\u003e\n\u003cli\u003eThe SSRF payload exploits the target service or local system component to execute system-level commands.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution, granting persistent access or the ability to perform further post-exploitation actions on the host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-34361 results in full remote code execution on the server hosting the Pi-hole instance. This allows attackers to exfiltrate sensitive network configurations, pivot to other internal network segments, or disrupt DNS resolution services provided by the sinkhole. Given the common deployment of Pi-hole as a central network-wide DNS filtering mechanism, compromise of this host represents a significant threat to internal visibility and security controls.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately upgrade all instances of Pi-hole to version 5.18.3 or later to mitigate CVE-2024-34361.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Pi-hole administration interface to trusted management networks only, preventing unauthorized authentication that acts as a prerequisite for this exploit.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect and filter suspicious traffic containing protocol handlers like 'gopher://' or anomalous URI query parameters targeting 'admin/login.php'.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate DNS infrastructure from critical internal service segments to limit the blast radius of a potential SSRF-based pivot.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T10:27:39Z","date_published":"2026-09-18T10:27:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pihole-ssrf-rce/","summary":"Pi-hole versions 5.18.2 and earlier are vulnerable to an authenticated SSRF attack via improper URL validation, which can be chained with the Gopherus protocol to achieve remote code execution on the host system.","title":"Pi-hole SSRF to RCE Vulnerability via CVE-2024-34361","url":"https://feed.craftedsignal.io/briefs/2026-09-pihole-ssrf-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Pi-Hole (\u003c= 5.18.2)","version":"https://jsonfeed.org/version/1.1"}