Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PowerDNS — Vulnerabilities & Security Advisories 75

Browse all 75 CVE security advisories affecting PowerDNS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PowerDNS is an open-source authoritative and recursive DNS server widely deployed to resolve domain names for internet infrastructure. Its extensive attack surface has resulted in fifty-three recorded CVEs, reflecting the complexity of its configuration and extension mechanisms. Historically, vulnerabilities have predominantly involved remote code execution, buffer overflows, and denial-of-service conditions, often stemming from improper input validation in the recursor or authoritative server components. While the software itself is robust, security incidents frequently arise from misconfigurations or unpatched third-party modules rather than fundamental architectural flaws. The project maintains a responsible disclosure process, though the high volume of past issues highlights the challenges of maintaining security in a feature-rich, C++-based codebase. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with these known weaknesses in the DNS resolution ecosystem.

CVE IDTitleCVSSSeverityPublished
CVE-2025-30194 Denial of service via crafted DoH exchange — DNSdistCWE-416 7.5 High2025-04-29
CVE-2025-30195 A crafted zone can lead to an illegal memory access in the PowerDNS Recursor — RecursorCWE-476 7.5 High2025-04-07
CVE-2024-25590 Crafted responses can lead to a denial of service due to cache inefficiencies in the Recursor — RecursorCWE-20 7.5 High2024-10-03
CVE-2024-25581 Transfer requests received over DoH can lead to a denial of service in DNSdist — DNSdistCWE-20 7.5 High2024-05-13
CVE-2024-25583 Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configured — RecursorCWE-20 7.5 High2024-04-25
CVE-2023-26437 Deterred spoofing attempts can lead to authoritative servers being marked unavailable — Recursor 3.4 Low2023-04-04
CVE-2015-5230 PowerDNS Authoritative Server 输入验证错误漏洞 — PowerDNS Authoritative Server 7.5 -2020-01-15
CVE-2019-10163 PowerDNS Authoritative Server 资源管理错误漏洞 — pdnsCWE-770 6.5 -2019-07-30
CVE-2019-10162 PowerDNS Authoritative Server 授权问题漏洞 — pdnsCWE-400 7.5 -2019-07-30
CVE-2017-15120 PowerDNS Recursor 安全漏洞 — pdns-recursorCWE-476 7.5 -2018-07-27
CVE-2017-15094 PowerDNS Recursor 安全漏洞 — PowerDNS RecursorCWE-401 5.9 -2018-01-23
CVE-2017-15093 PowerDNS Recursor 安全漏洞 — PowerDNS RecursorCWE-20 5.3 -2018-01-23
CVE-2017-15092 PowerDNS Recursor 跨站脚本漏洞 — PowerDNS RecursorCWE-79 6.1 -2018-01-23
CVE-2017-15091 PowerDNS Authoritative API组件安全漏洞 — PowerDNS AuthoritativeCWE-863 7.1 -2018-01-23
CVE-2017-15090 PowerDNS Recursor DNSSEC验证组件安全漏洞 — PowerDNSCWE-347 5.9 -2018-01-23

This page lists every published CVE security advisory associated with PowerDNS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.