Skip to main content

Vendor/product archive

powerdns / recursor CVEs

Beta · best-effort

50 CVEs tagged to powerdns / recursor1 Critical, 17 High, 29 Medium, 3 Low, 0 Unrated.

CVE-2026-33601

Published Apr 22, 2026

If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency c…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33600

Published Apr 22, 2026

An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33262

Published Apr 22, 2026

An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33261

Published Apr 22, 2026

A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33259

Published Apr 22, 2026

Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zo…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33258

Published Apr 22, 2026

By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33256

Published Apr 22, 2026

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by defau…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24027

Published Feb 9, 2026

Crafted zones can lead to increased incoming network traffic.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0398

Published Feb 9, 2026

Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59030

Published Dec 9, 2025

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59029

Published Dec 9, 2025

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50868

Published Feb 14, 2024

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2023-50387

Published Feb 14, 2024

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2023-26437

Published Apr 4, 2023

Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22617

Published Jan 21, 2023

A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured domain, because QName minimiza…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-37428

Published Aug 23, 2022

PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14196

Published Jul 1, 2020

In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10030

Published May 19, 2020

An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's hostname) to cause disclosure of…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 50 CVEsPage 1 of 2