Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PowerDNS — Vulnerabilities & Security Advisories 75

Browse all 75 CVE security advisories affecting PowerDNS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PowerDNS is an open-source authoritative and recursive DNS server widely deployed to resolve domain names for internet infrastructure. Its extensive attack surface has resulted in fifty-three recorded CVEs, reflecting the complexity of its configuration and extension mechanisms. Historically, vulnerabilities have predominantly involved remote code execution, buffer overflows, and denial-of-service conditions, often stemming from improper input validation in the recursor or authoritative server components. While the software itself is robust, security incidents frequently arise from misconfigurations or unpatched third-party modules rather than fundamental architectural flaws. The project maintains a responsible disclosure process, though the high volume of past issues highlights the challenges of maintaining security in a feature-rich, C++-based codebase. Administrators must prioritize regular updates and strict access controls to mitigate risks associated with these known weaknesses in the DNS resolution ecosystem.

CVE IDTitleCVSSSeverityPublished
CVE-2026-52688 RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation — Recursor 7.5 High2026-07-23
CVE-2026-52686 Wildcard CNAME proof validation bypass — Recursor 3.7 Low2026-07-23
CVE-2026-52684 Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack — Recursor 3.7 Low2026-07-23
CVE-2026-42389 Reject more queries with invalid header values — Recursor 5.3 Medium2026-06-25
CVE-2026-52690 Spoofed answers can mark an authoritative non-EDNS capable — Recursor 5.9 Medium2026-06-25
CVE-2026-42390 ZONEMD validation can be bypassed — Recursor 5.3 Medium2026-06-25
CVE-2026-42388 Missing input validation for catalog zones — Recursor 5.9 Medium2026-06-25
CVE-2026-42387 Insufficient input validation in ZoneToCache — Recursor 5.9 Medium2026-06-25
CVE-2026-40012 Information about ECS zero scoped answers might leak to clients that use a specific ECS — Recursor 5.3 Medium2026-06-25
CVE-2026-33612 ZoneToCache can poison the cache — Recursor 7.5 High2026-06-25
CVE-2026-42004 EDNS options smuggling — DNSdist 3.7 Low2026-06-25
CVE-2026-40211 Denial of service via crafted DoH3 queries — DNSdist 5.3 Medium2026-06-25
CVE-2026-40210 Out-of-bounds read in SetMacAddrAction — DNSdist 4.8 Medium2026-06-25
CVE-2026-40209 Denial of service via IXFR queries — DNSdist 5.3 Medium2026-06-25
CVE-2026-40208 Denial of service via DoH3 queries — DNSdist 3.7 Low2026-06-25
CVE-2026-40011 Prometheus denial of service via crafted DNS queries — DNSdist 3.7 Low2026-06-25
CVE-2026-42005 Insufficient input validation of internal web server — Authoritative 4.3 Medium2026-06-25
CVE-2026-41999 Incorrect Behaviour of Views with TCP PROXY Requests — Authoritative 4.8 Medium2026-05-21
CVE-2026-42002 Concurrency and locking defects in GSS-TSIG — Authoritative 5.9 Medium2026-05-21
CVE-2026-42001 Insufficient Validation of Autoprimary SOA Queries — Authoritative 7.5 High2026-05-21
CVE-2026-42000 Insufficient Validation of Names During AXFR — Authoritative 6.8 Medium2026-05-21
CVE-2026-42396 Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail — Authoritative 4.9 Medium2026-05-21
CVE-2026-33611 Insufficient validation of HTTPS and SVCB records — Authoritative 6.5 Medium2026-04-22
CVE-2026-33610 Possible file descriptor exhaustion in forward-dnsupdate — Authoritative 5.9 Medium2026-04-22
CVE-2026-33609 LDAP DN injection — Authoritative 5.3 Medium2026-04-22
CVE-2026-33608 Incomplete domain name sanitization during — Authoritative 7.4 High2026-04-22
CVE-2026-33593 Denial of service via crafted DNSCrypt query — DNSdist 7.5 High2026-04-22
CVE-2026-33594 Outgoing DoH excessive memory allocation — DNSdist 5.3 Medium2026-04-22
CVE-2026-33595 DoQ/DoH3 excessive memory allocation — DNSdist 5.3 Medium2026-04-22
CVE-2026-33597 PRSD detection denial of service — DNSdist 3.7 Low2026-04-22

This page lists every published CVE security advisory associated with PowerDNS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.