Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PowerDNS — Vulnerabilities & Security Advisories 75

Browse all 75 CVE security advisories affecting PowerDNS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PowerDNS is an open-source authoritative and recursive DNS server widely deployed to resolve domain names for internet infrastructure. Its extensive attack surface has resulted in fifty-three recorded CVEs, reflecting the complexity of its configuration and extension mechanisms. Historically, vulnerabilities have predominantly involved remote code execution, buffer overflows, and denial-of-service conditions, often stemming from improper input validation in the recursor or authoritative server components. While the software itself is robust, security incidents frequently arise from misconfigurations or unpatched third-party modules rather than fundamental architectural flaws. The project maintains a responsible disclosure process, though the high volume of past issues highlights the challenges of maintaining security in a feature-rich, C++-based codebase. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with these known weaknesses in the DNS resolution ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-52688 RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation — Recursor 7.5 High 2026-07-23
CVE-2026-52686 Wildcard CNAME proof validation bypass — Recursor 3.7 Low 2026-07-23
CVE-2026-52684 Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack — Recursor 3.7 Low 2026-07-23
CVE-2026-42389 Reject more queries with invalid header values — Recursor 5.3 Medium 2026-06-25
CVE-2026-52690 Spoofed answers can mark an authoritative non-EDNS capable — Recursor 5.9 Medium 2026-06-25
CVE-2026-42390 ZONEMD validation can be bypassed — Recursor 5.3 Medium 2026-06-25
CVE-2026-42388 Missing input validation for catalog zones — Recursor 5.9 Medium 2026-06-25
CVE-2026-42387 Insufficient input validation in ZoneToCache — Recursor 5.9 Medium 2026-06-25
CVE-2026-40012 Information about ECS zero scoped answers might leak to clients that use a specific ECS — Recursor 5.3 Medium 2026-06-25
CVE-2026-33612 ZoneToCache can poison the cache — Recursor 7.5 High 2026-06-25
CVE-2026-42004 EDNS options smuggling — DNSdist 3.7 Low 2026-06-25
CVE-2026-40211 Denial of service via crafted DoH3 queries — DNSdist 5.3 Medium 2026-06-25
CVE-2026-40210 Out-of-bounds read in SetMacAddrAction — DNSdist 4.8 Medium 2026-06-25
CVE-2026-40209 Denial of service via IXFR queries — DNSdist 5.3 Medium 2026-06-25
CVE-2026-40208 Denial of service via DoH3 queries — DNSdist 3.7 Low 2026-06-25
CVE-2026-40011 Prometheus denial of service via crafted DNS queries — DNSdist 3.7 Low 2026-06-25
CVE-2026-42005 Insufficient input validation of internal web server — Authoritative 4.3 Medium 2026-06-25
CVE-2026-41999 Incorrect Behaviour of Views with TCP PROXY Requests — Authoritative 4.8 Medium 2026-05-21
CVE-2026-42002 Concurrency and locking defects in GSS-TSIG — Authoritative 5.9 Medium 2026-05-21
CVE-2026-42001 Insufficient Validation of Autoprimary SOA Queries — Authoritative 7.5 High 2026-05-21
CVE-2026-42000 Insufficient Validation of Names During AXFR — Authoritative 6.8 Medium 2026-05-21
CVE-2026-42396 Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail — Authoritative 4.9 Medium 2026-05-21
CVE-2026-33611 Insufficient validation of HTTPS and SVCB records — Authoritative 6.5 Medium 2026-04-22
CVE-2026-33610 Possible file descriptor exhaustion in forward-dnsupdate — Authoritative 5.9 Medium 2026-04-22
CVE-2026-33609 LDAP DN injection — Authoritative 5.3 Medium 2026-04-22
CVE-2026-33608 Incomplete domain name sanitization during — Authoritative 7.4 High 2026-04-22
CVE-2026-33593 Denial of service via crafted DNSCrypt query — DNSdist 7.5 High 2026-04-22
CVE-2026-33594 Outgoing DoH excessive memory allocation — DNSdist 5.3 Medium 2026-04-22
CVE-2026-33595 DoQ/DoH3 excessive memory allocation — DNSdist 5.3 Medium 2026-04-22
CVE-2026-33597 PRSD detection denial of service — DNSdist 3.7 Low 2026-04-22

This page lists every published CVE security advisory associated with PowerDNS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.