8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based web server. This issue has been patched in version 6.6.1.
AI Analysis
Unauthenticated session hijacking via race condition on global session buffer in Pi-hole FTL
Basic Information
ID
CVE-2026-44693
Source
GitHub_M
Published
Jun 10, 2026 at 22:11
Affected Product
Vendor
pi-hole
Product
FTL
Version
< 6.6.1
Affected Versions
pi-hole FTL < 6.6.1
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Pi-hole
Product
Pi-hole FTL
Version
< 6.6.1