Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PowerDNS — Vulnerabilities & Security Advisories 75

Browse all 75 CVE security advisories affecting PowerDNS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PowerDNS is an open-source authoritative and recursive DNS server widely deployed to resolve domain names for internet infrastructure. Its extensive attack surface has resulted in fifty-three recorded CVEs, reflecting the complexity of its configuration and extension mechanisms. Historically, vulnerabilities have predominantly involved remote code execution, buffer overflows, and denial-of-service conditions, often stemming from improper input validation in the recursor or authoritative server components. While the software itself is robust, security incidents frequently arise from misconfigurations or unpatched third-party modules rather than fundamental architectural flaws. The project maintains a responsible disclosure process, though the high volume of past issues highlights the challenges of maintaining security in a feature-rich, C++-based codebase. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with these known weaknesses in the DNS resolution ecosystem.

CVE ID Title CVSS Severity Published
CVE-2025-30194 Denial of service via crafted DoH exchange — DNSdist CWE-416 7.5 High 2025-04-29
CVE-2025-30195 A crafted zone can lead to an illegal memory access in the PowerDNS Recursor — Recursor CWE-476 7.5 High 2025-04-07
CVE-2024-25590 Crafted responses can lead to a denial of service due to cache inefficiencies in the Recursor — Recursor CWE-20 7.5 High 2024-10-03
CVE-2024-25581 Transfer requests received over DoH can lead to a denial of service in DNSdist — DNSdist CWE-20 7.5 High 2024-05-13
CVE-2024-25583 Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configured — Recursor CWE-20 7.5 High 2024-04-25
CVE-2023-26437 Deterred spoofing attempts can lead to authoritative servers being marked unavailable — Recursor 3.4 Low 2023-04-04
CVE-2015-5230 PowerDNS Authoritative Server 输入验证错误漏洞 — PowerDNS Authoritative Server 7.5 - 2020-01-15
CVE-2019-10163 PowerDNS Authoritative Server 资源管理错误漏洞 — pdns CWE-770 6.5 - 2019-07-30
CVE-2019-10162 PowerDNS Authoritative Server 授权问题漏洞 — pdns CWE-400 7.5 - 2019-07-30
CVE-2017-15120 PowerDNS Recursor 安全漏洞 — pdns-recursor CWE-476 7.5 - 2018-07-27
CVE-2017-15094 PowerDNS Recursor 安全漏洞 — PowerDNS Recursor CWE-401 5.9 - 2018-01-23
CVE-2017-15093 PowerDNS Recursor 安全漏洞 — PowerDNS Recursor CWE-20 5.3 - 2018-01-23
CVE-2017-15092 PowerDNS Recursor 跨站脚本漏洞 — PowerDNS Recursor CWE-79 6.1 - 2018-01-23
CVE-2017-15091 PowerDNS Authoritative API组件安全漏洞 — PowerDNS Authoritative CWE-863 7.1 - 2018-01-23
CVE-2017-15090 PowerDNS Recursor DNSSEC验证组件安全漏洞 — PowerDNS CWE-347 5.9 - 2018-01-23

This page lists every published CVE security advisory associated with PowerDNS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.