πŸ” CVE Alert

CVE-2026-26953

MEDIUM 5.4

Pi-hole Web Interface has Stored HTML Injection via X-Forwarded-For Header in Active Sessions Table

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions table located on the API settings page, allowing an attacker with valid credentials to inject arbitrary HTML code that will be rendered in the browser of any administrator who visits the active sessions page. The rowCallback function contains the value data.x_forwarded_for, which is directly concatenated into an HTML string and inserted into the DOM using jQuery’s .html() method. This method interprets the content as HTML, which means that any HTML tags present in the value will be parsed and rendered by the browser. An attacker can use common tools such as curl, wget, Python requests, Burp Suite, or even JavaScript fetch() to send an authentication request with an X-Forwarded-For header that contains malicious HTML code instead of a legitimate IP address. Since Pi-hole implements a Content Security Policy (CSP) that blocks inline JavaScript, the impact is limited to pure HTML injection without the ability to execute scripts. This issue has been fixed in version 6.4.1.

CWE CWE-20 CWE-116 CWE-79
Vendor pi-hole
Product web
Published Feb 19, 2026
Last Updated Feb 20, 2026
Stay Ahead of the Next One

Get instant alerts for pi-hole web

Be the first to know when new medium vulnerabilities affecting pi-hole web are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

pi-hole / web
< 6.4.1

References

NVD β†— CVE.org β†— EPSS Data β†—
github.com: https://github.com/pi-hole/web/security/advisories/GHSA-8rw8-vjgp-rwj6 github.com: https://github.com/pi-hole/web/commit/1a0c6f4fe6d0116fd2846b2adaae95996b7f194d github.com: https://github.com/pi-hole/web/releases/tag/v6.4.1