CRLF Injection Affecting pi-hole/ftl package, versions [,6.6.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.96% (57th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-PIHOLEFTL-16424122
  • published6 May 2026
  • disclosed5 May 2026
  • creditanuraagbaishya

Introduced: 5 May 2026

CVE-2026-39849  (opens in a new tab)
CWE-93  (opens in a new tab)

How to fix?

Upgrade pi-hole/ftl to version 6.6.1 or higher.

Overview

Affected versions of this package are vulnerable to CRLF Injection via the dns.interface configuration field, which accepts newline characters without validation. An attacker can execute arbitrary commands on the host by injecting malicious directives into the generated dnsmasq configuration file through the configuration API. This is only exploitable if no admin password is set, allowing full access to the configuration API without credentials.

CVSS Base Scores

version 4.0
version 3.1