Skip to main content

Vendor/product archive

powerdns / authoritative CVEs

Beta · best-effort

31 CVEs tagged to powerdns / authoritative1 Critical, 12 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2026-42396

Published May 21, 2026

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33611

Published Apr 22, 2026

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33610

Published Apr 22, 2026

A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS update request to it.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33609

Published Apr 22, 2026

Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33608

Published Apr 22, 2026

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, le…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-24698

Published Oct 2, 2020

An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-fre…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-24697

Published Oct 2, 2020

An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can cause a denial of service by se…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24696

Published Oct 2, 2020

An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can trigger a race condition leadin…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-17482

Published Oct 2, 2020

An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the con…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5230

Published Jan 15, 2020

The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via crafted quer…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10162

Published Jul 30, 2019

A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14626

Published Nov 29, 2018

PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can l…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2