Skip to content
#

newline-injection

Here is 1 public repository matching this topic...

CVE-2026-35517 Pi-hole FTLDNS Remote Code Execution via Newline Injection (CVSS 8.8). Python & Nmap NSE detection scripts with full technical breakdown. A newline character in the dns.upstreams parameter gives authenticated attackers command execution on the host. Five related injection vectors all patched in FTL v6.6.

  • Updated Apr 14, 2026
  • Python

Improve this page

Add a description, image, and links to the newline-injection topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the newline-injection topic, visit your repo's landing page and select "manage topics."

Learn more