PowerDNS / Recursor
50 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-52688 | RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation | HIGH | 7.5 | Jul 23, 2026 |
| CVE-2026-52686 | Wildcard CNAME proof validation bypass | LOW | 3.7 | Jul 23, 2026 |
| CVE-2026-52684 | Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack | LOW | 3.7 | Jul 23, 2026 |
| CVE-2026-42389 | Reject more queries with invalid header values | MEDIUM | 5.3 | Jun 25, 2026 |
| CVE-2026-52690 | Spoofed answers can mark an authoritative non-EDNS capable | MEDIUM | 5.9 | Jun 25, 2026 |
| CVE-2026-42390 | ZONEMD validation can be bypassed | MEDIUM | 5.3 | Jun 25, 2026 |
| CVE-2026-42388 | Missing input validation for catalog zones | MEDIUM | 5.9 | Jun 25, 2026 |
| CVE-2026-42387 | Insufficient input validation in ZoneToCache | MEDIUM | 5.9 | Jun 25, 2026 |
| CVE-2026-40012 | Information about ECS zero scoped answers might leak to clients that use a specific ECS | MEDIUM | 5.3 | Jun 25, 2026 |
| CVE-2026-33612 | ZoneToCache can poison the cache | HIGH | 7.5 | Jun 25, 2026 |
| CVE-2026-33262 | Insufficient validation of cookie reply | MEDIUM | 5.9 | Apr 22, 2026 |
| CVE-2026-33261 | Null pointer accces in aggressive NSEC(3) cache | MEDIUM | 5.9 | Apr 22, 2026 |
| CVE-2026-33260 | Insufficient input validation of internal webserver | HIGH | 7.5 | Apr 22, 2026 |
| CVE-2026-33259 | Concurrent modification of RPZ data can lead to denial of servce | MEDIUM | 5.0 | Apr 22, 2026 |
| CVE-2026-33258 | Crafted zones can cause increased resource usage | HIGH | 7.5 | Apr 22, 2026 |
| CVE-2026-33257 | Insufficient input validation of internal webserver | HIGH | 7.5 | Apr 22, 2026 |
| CVE-2026-33256 | Unbounded memory allocation by internal web server | HIGH | 7.5 | Apr 22, 2026 |
| CVE-2026-33601 | Insufficient validation of zonemd record | MEDIUM | 4.9 | Apr 22, 2026 |
| CVE-2026-33600 | Null pointer dereference in RPZ transfer | MEDIUM | 4.9 | Apr 22, 2026 |
| CVE-2025-59024 | Crafted delegations or IP fragments can poison cached delegations in Recursor | MEDIUM | 6.5 | Feb 9, 2026 |
| CVE-2025-59023 | Crafted delegations or IP fragments can poison cached delegations in Recursor | HIGH | 8.2 | Feb 9, 2026 |
| CVE-2026-24027 | Crafted zones can lead to increased incoming network traffic | MEDIUM | 5.3 | Feb 9, 2026 |
| CVE-2026-0398 | Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor | MEDIUM | 5.3 | Feb 9, 2026 |
| CVE-2025-59029 | Internal logic flaw in cache management can lead to a denial of service in PowerDNS Recursor | MEDIUM | 5.3 | Dec 9, 2025 |
| CVE-2025-59030 | Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor | HIGH | 7.5 | Dec 9, 2025 |
Showing 1 to 25 of 50 CVEs