Vendor
high
advisory
Pi-hole SSRF to RCE Vulnerability via CVE-2024-34361
1 rule 2 TTPs 1 CVEPi-hole versions 5.18.2 and earlier are vulnerable to an authenticated SSRF attack via improper URL validation, which can be chained with the Gopherus protocol to achieve remote code execution on the host system.
Pi-hole
vulnerability
rce
ssrf
1r
2t
1c
critical
advisory
Pi-hole FTL Remote Code Execution Vulnerability (CVE-2026-35519)
2 rules 1 TTP 1 CVEA remote code execution vulnerability exists in Pi-hole FTL versions 6.0 to before 6.6, where an authenticated attacker can inject arbitrary dnsmasq configuration directives through newline characters in the DNS host record configuration parameter, leading to command execution on the underlying system.
Pi-hole
pihole
rce
dnsmasq
cve-2026-35519
2r
1t
1c