Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

PowerDNS — Vulnerabilities & Security Advisories 53

Browse all 53 CVE security advisories affecting PowerDNS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2026-33611 Insufficient validation of HTTPS and SVCB records — Authoritative 6.5 Medium2026-04-22
CVE-2026-33610 Possible file descriptor exhaustion in forward-dnsupdate — Authoritative 5.9 Medium2026-04-22
CVE-2026-33609 LDAP DN injection — Authoritative 5.3 Medium2026-04-22
CVE-2026-33608 Incomplete domain name sanitization during — Authoritative 7.4 High2026-04-22
CVE-2026-33593 Denial of service via crafted DNSCrypt query — DNSdist 7.5 High2026-04-22
CVE-2026-33594 Outgoing DoH excessive memory allocation — DNSdist 5.3 Medium2026-04-22
CVE-2026-33595 DoQ/DoH3 excessive memory allocation — DNSdist 5.3 Medium2026-04-22
CVE-2026-33597 PRSD detection denial of service — DNSdist 3.7 Low2026-04-22
CVE-2026-33596 TCP backend stream ID overflow — DNSdist 3.1 Low2026-04-22
CVE-2026-33598 Out-of-bounds read in cache inspection via Lua — DNSdist 4.8 Medium2026-04-22
CVE-2026-33599 Out-of-bounds read in service discovery — DNSdist 3.1 Low2026-04-22
CVE-2026-33602 Off-by-one access when processing crafted UDP responses — DNSdist 6.5 Medium2026-04-22
CVE-2026-33254 Resource exhaustion via DoQ/DoH3 connections — DNSdist 5.3 Medium2026-04-22
CVE-2026-33262 Insufficient validation of cookie reply — Recursor 5.9 Medium2026-04-22
CVE-2026-33261 Null pointer accces in aggressive NSEC(3) cache — Recursor 5.9 Medium2026-04-22
CVE-2026-33260 Insufficient input validation of internal webserver — Authoritative 5.3 Medium2026-04-22
CVE-2026-33259 Concurrent modification of RPZ data can lead to denial of servce — Recursor 5.0 Medium2026-04-22
CVE-2026-33258 Crafted zones can cause increased resource usage — Recursor 5.3 Medium2026-04-22
CVE-2026-33257 Insufficient input validation of internal webserver — Authoritative 5.3 Medium2026-04-22
CVE-2026-33256 Unbounded memory allocation by internal web server — Recursor 5.3 Medium2026-04-22
CVE-2026-33601 Insufficient validation of zonemd record — Recursor 4.4 Medium2026-04-22
CVE-2026-33600 Null pointer dereference in RPZ transfer — Recursor 4.4 Medium2026-04-22
CVE-2026-27854 Use after free when parsing EDNS options in Lua — DNSdist 4.8 Medium2026-03-31
CVE-2026-27853 Out-of-bounds write when rewriting large DNS packets — DNSdist 5.9 Medium2026-03-31
CVE-2026-24030 Unbounded memory allocation for DoQ and DoH3 — DNSdist 5.3 Medium2026-03-31
CVE-2026-24029 DNS over HTTPS ACL bypass — DNSdist 6.5 Medium2026-03-31
CVE-2026-24028 Out-of-bounds read when parsing DNS packets via Lua — DNSdist 5.3 Medium2026-03-31
CVE-2026-0397 Information disclosure via CORS misconfiguration — DNSdist 3.1 Low2026-03-31
CVE-2026-0396 HTML injection in the web dashboard — DNSdist 3.1 Low2026-03-31
CVE-2025-59024 Crafted delegations or IP fragments can poison cached delegations in Recursor — Recursor 6.5 Medium2026-02-09

This page lists every published CVE security advisory associated with PowerDNS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.