Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Recursor — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in Recursor, with AI-generated Chinese analysis, references, and POCs.

This page documents common software weaknesses associated with the Recursor product, covering a range of vulnerability types including buffer overflows, injection flaws, and improper access controls. It serves as a centralized repository for aggregating security issues that affect the DNS resolution capabilities and operational stability of recursive nameservers deployed in various enterprise and service provider environments. The collected data encompasses a broad spectrum of critical severity ratings, reflecting both theoretical attack vectors and exploited weaknesses found in real-world scenarios over the past five years. Here, security professionals can track vendor advisories for the Recursor software family to stay informed about patches and mitigations. Users can also gain a deeper understanding of specific weakness classes by analyzing recurring patterns in reported incidents, which helps in prioritizing remediation efforts based on historical data. Additionally, the page allows for the lookup of a specific product version’s vulnerability history, enabling teams to assess their exposure against known issues. By consolidating these diverse data points, the resource supports proactive threat modeling and strengthens the overall security posture of DNS infrastructure. This approach ensures that administrators have access to comprehensive insights, facilitating better decision-making regarding updates, configuration hardening, and network segmentation strategies to protect against potential exploitation of these identified weaknesses.

Vendor: PowerDNS

CVE IDTitleCVSSSeverityPublished
CVE-2026-42389 Reject more queries with invalid header values 5.3 Medium2026-06-25
CVE-2026-52690 Spoofed answers can mark an authoritative non-EDNS capable 5.9 Medium2026-06-25
CVE-2026-42390 ZONEMD validation can be bypassed 5.3 Medium2026-06-25
CVE-2026-42388 Missing input validation for catalog zones 5.9 Medium2026-06-25
CVE-2026-42387 Insufficient input validation in ZoneToCache 5.9 Medium2026-06-25
CVE-2026-40012 Information about ECS zero scoped answers might leak to clients that use a specific ECS 5.3 Medium2026-06-25
CVE-2026-33612 ZoneToCache can poison the cache 7.5 High2026-06-25
CVE-2026-33262 Insufficient validation of cookie reply 5.9 Medium2026-04-22
CVE-2026-33261 Null pointer accces in aggressive NSEC(3) cache 5.9 Medium2026-04-22
CVE-2026-33259 Concurrent modification of RPZ data can lead to denial of servce 5.0 Medium2026-04-22
CVE-2026-33258 Crafted zones can cause increased resource usage 5.3 Medium2026-04-22
CVE-2026-33256 Unbounded memory allocation by internal web server 5.3 Medium2026-04-22
CVE-2026-33601 Insufficient validation of zonemd record 4.4 Medium2026-04-22
CVE-2026-33600 Null pointer dereference in RPZ transfer 4.4 Medium2026-04-22
CVE-2025-59024 Crafted delegations or IP fragments can poison cached delegations in Recursor 6.5 Medium2026-02-09
CVE-2025-59023 Crafted delegations or IP fragments can poison cached delegations in Recursor 8.2 High2026-02-09
CVE-2026-24027 Crafted zones can lead to increased incoming network traffic 5.3 Medium2026-02-09
CVE-2026-0398 Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor 5.3 Medium2026-02-09
CVE-2025-59029 Internal logic flaw in cache management can lead to a denial of service in PowerDNS Recursor CWE-617 5.3 Medium2025-12-09
CVE-2025-59030 Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor CWE-276 7.5 High2025-12-09
CVE-2025-30192 A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempts CWE-345 7.5 High2025-07-21
CVE-2025-30195 A crafted zone can lead to an illegal memory access in the PowerDNS Recursor CWE-476 7.5 High2025-04-07
CVE-2024-25590 Crafted responses can lead to a denial of service due to cache inefficiencies in the Recursor CWE-20 7.5 High2024-10-03
CVE-2024-25583 Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configured CWE-20 7.5 High2024-04-25
CVE-2023-26437 Deterred spoofing attempts can lead to authoritative servers being marked unavailable 3.4 Low2023-04-04

All 25 known CVE vulnerabilities affecting Recursor with full Chinese analysis, references, and POCs where available.