Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PowerDNS — Vulnerabilities & Security Advisories 75

Browse all 75 CVE security advisories affecting PowerDNS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PowerDNS is an open-source authoritative and recursive DNS server widely deployed to resolve domain names for internet infrastructure. Its extensive attack surface has resulted in fifty-three recorded CVEs, reflecting the complexity of its configuration and extension mechanisms. Historically, vulnerabilities have predominantly involved remote code execution, buffer overflows, and denial-of-service conditions, often stemming from improper input validation in the recursor or authoritative server components. While the software itself is robust, security incidents frequently arise from misconfigurations or unpatched third-party modules rather than fundamental architectural flaws. The project maintains a responsible disclosure process, though the high volume of past issues highlights the challenges of maintaining security in a feature-rich, C++-based codebase. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with these known weaknesses in the DNS resolution ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-33596 TCP backend stream ID overflow — DNSdist 3.1 Low 2026-04-22
CVE-2026-33598 Out-of-bounds read in cache inspection via Lua — DNSdist 4.8 Medium 2026-04-22
CVE-2026-33599 Out-of-bounds read in service discovery — DNSdist 3.1 Low 2026-04-22
CVE-2026-33602 Off-by-one access when processing crafted UDP responses — DNSdist 6.5 Medium 2026-04-22
CVE-2026-33254 Resource exhaustion via DoQ/DoH3 connections — DNSdist 5.3 Medium 2026-04-22
CVE-2026-33262 Insufficient validation of cookie reply — Recursor 5.9 Medium 2026-04-22
CVE-2026-33261 Null pointer accces in aggressive NSEC(3) cache — Recursor 5.9 Medium 2026-04-22
CVE-2026-33260 Insufficient input validation of internal webserver — Authoritative 5.3 Medium 2026-04-22
CVE-2026-33259 Concurrent modification of RPZ data can lead to denial of servce — Recursor 5.0 Medium 2026-04-22
CVE-2026-33258 Crafted zones can cause increased resource usage — Recursor 5.3 Medium 2026-04-22
CVE-2026-33257 Insufficient input validation of internal webserver — Authoritative 5.3 Medium 2026-04-22
CVE-2026-33256 Unbounded memory allocation by internal web server — Recursor 5.3 Medium 2026-04-22
CVE-2026-33601 Insufficient validation of zonemd record — Recursor 4.4 Medium 2026-04-22
CVE-2026-33600 Null pointer dereference in RPZ transfer — Recursor 4.4 Medium 2026-04-22
CVE-2026-27854 Use after free when parsing EDNS options in Lua — DNSdist 4.8 Medium 2026-03-31
CVE-2026-27853 Out-of-bounds write when rewriting large DNS packets — DNSdist 5.9 Medium 2026-03-31
CVE-2026-24030 Unbounded memory allocation for DoQ and DoH3 — DNSdist 5.3 Medium 2026-03-31
CVE-2026-24029 DNS over HTTPS ACL bypass — DNSdist 6.5 Medium 2026-03-31
CVE-2026-24028 Out-of-bounds read when parsing DNS packets via Lua — DNSdist 5.3 Medium 2026-03-31
CVE-2026-0397 Information disclosure via CORS misconfiguration — DNSdist 3.1 Low 2026-03-31
CVE-2026-0396 HTML injection in the web dashboard — DNSdist 3.1 Low 2026-03-31
CVE-2025-59024 Crafted delegations or IP fragments can poison cached delegations in Recursor — Recursor 6.5 Medium 2026-02-09
CVE-2025-59023 Crafted delegations or IP fragments can poison cached delegations in Recursor — Recursor 8.2 High 2026-02-09
CVE-2026-24027 Crafted zones can lead to increased incoming network traffic — Recursor 5.3 Medium 2026-02-09
CVE-2026-0398 Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor — Recursor 5.3 Medium 2026-02-09
CVE-2025-59029 Internal logic flaw in cache management can lead to a denial of service in PowerDNS Recursor — Recursor CWE-617 5.3 Medium 2025-12-09
CVE-2025-59030 Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor — Recursor CWE-276 7.5 High 2025-12-09
CVE-2025-30187 Denial of service via crafted DoH exchange in PowerDNS DNSdist — DNSdist CWE-835 3.7 Low 2025-09-18
CVE-2025-30192 A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempts — Recursor CWE-345 7.5 High 2025-07-21
CVE-2025-30193 Denial of service via crafted TCP exchange — DNSdist CWE-674 7.5 High 2025-05-20

This page lists every published CVE security advisory associated with PowerDNS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.