Home/Product/powerdns recursor
Product

powerdns recursor

101 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-33611
>= 4.9.0 and < 4.9.14
An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can
6.5MEDIUM
CVE-2026-33610
>= 4.9.0 and < 4.9.14
A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server f
5.9MEDIUM
CVE-2026-33609
>= 4.9.0 and < 4.9.14
Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees
5.3MEDIUM
CVE-2026-33608
>= 4.9.0 and < 4.9.14
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend
7.4HIGH
CVE-2026-33602
>= 1.9.0 and < 1.9.13
A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an
6.5MEDIUM
CVE-2026-33599
>= 1.9.0 and < 1.9.13
A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the aut
3.1LOW
CVE-2026-33598
>= 1.9.0 and < 1.9.13
A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDom
4.8MEDIUM
CVE-2026-33597
>= 1.9.0 and < 1.9.13
PRSD detection denial of service
3.7LOW
CVE-2026-33596
>= 1.9.0 and < 1.9.13
A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a
3.1LOW
CVE-2026-33595
>= 1.9.0 and < 1.9.13
A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as
5.3MEDIUM
CVE-2026-33594
>= 1.9.0 and < 1.9.13
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, caus
5.3MEDIUM
CVE-2026-33593
>= 1.9.0 and < 1.9.13
A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.
7.5HIGH
CVE-2026-33254
>= 1.9.0 and < 1.9.13
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and le
5.3MEDIUM
CVE-2026-33601
>= 5.2.0 and < 5.2.9
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null point
4.4MEDIUM
CVE-2026-33600
>= 5.2.0 and < 5.2.9
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check an
4.4MEDIUM
CVE-2026-33262
>= 5.2.0 and < 5.2.9
An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a den
5.9MEDIUM
CVE-2026-33261
>= 5.2.0 and < 5.2.9
A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
5.9MEDIUM
CVE-2026-33260
>= 5.2.0 and < 5.2.9
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of serv
5.3MEDIUM
CVE-2026-33259
>= 5.2.0 and < 5.2.9
Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor.
5.0MEDIUM
CVE-2026-33258
>= 5.2.0 and < 5.2.9
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3)
5.3MEDIUM
CVE-2026-33257
>= 5.2.0 and < 5.2.9
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of serv
5.3MEDIUM
CVE-2026-33256
>= 5.2.0 and < 5.2.9
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of serv
5.3MEDIUM
CVE-2026-27854
>= 1.9.0 and < 1.9.12
An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOpt
4.8MEDIUM
CVE-2026-27853
>= 1.9.0 and < 1.9.12
An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:ch
5.9MEDIUM
CVE-2026-24030
>= 1.9.0 and < 1.9.12
An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 paylo
5.3MEDIUM
CVE-2026-24029
>= 1.9.0 and < 1.9.12
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghtt
6.5MEDIUM
CVE-2026-24028
>= 1.9.0 and < 1.9.12
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses new
5.3MEDIUM
CVE-2026-0397
>= 1.9.0 and < 1.9.12
When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the da
3.1LOW
CVE-2026-0396
>= 1.9.0 and < 1.9.12
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist insta
3.1LOW
CVE-2026-24027
>= 5.1.0 and < 5.1.10
Crafted zones can lead to increased incoming network traffic.
5.3MEDIUM
CVE-2026-0398
>= 5.1.0 and < 5.1.10
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
5.3MEDIUM
CVE-2025-59024
>= 5.1.0 and < 5.1.8
Crafted delegations or IP fragments can poison cached delegations in Recursor.
6.5MEDIUM
CVE-2025-59023
>= 5.1.0 and < 5.1.8
Crafted delegations or IP fragments can poison cached delegations in Recursor.
8.2HIGH
CVE-2025-59030
>= 5.1.0 and < 5.1.9
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
7.5HIGH
CVE-2025-59029
all versions
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records c
5.3MEDIUM
CVE-2023-50868
< 4.8.5
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to c
7.5HIGH
CVE-2023-50387
>= 4.8.0 and < 4.8.6
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a den
7.5HIGH
CVE-2023-26437
< 4.6.6
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recu
3.4LOW
CVE-2023-22617
all versions
A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records f
7.5HIGH
CVE-2022-37428
>= 4.5.0 and < 4.5.10
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown
6.5MEDIUM
CVE-2022-27227
< 4.4.8
In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.
7.5HIGH
CVE-2021-36754
>= 4.5.0 and < 4.5.1
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) tha
7.5HIGH
CVE-2020-25829
< 4.1.18
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can caus
7.5HIGH
CVE-2020-24698
<= 4.3.0
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthentic
9.8CRITICAL
CVE-2020-24697
<= 4.3.0
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthentic
7.5HIGH
CVE-2020-24696
<= 4.3.0
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthentic
8.1HIGH
CVE-2020-17482
< 4.3.1
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted
4.3MEDIUM
CVE-2020-14196
<= 4.1.16
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server i
5.3MEDIUM
CVE-2020-10995
>= 4.1.0 and <= 4.3.0
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the
7.5HIGH
CVE-2020-10030
>= 4.1.0 and <= 4.3.0
An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to cha
8.8HIGH
CVE-2020-12244
>= 4.1.0 and <= 4.3.0
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lackin
7.5HIGH
CVE-2015-5230
>= 3.4.0 and < 3.4.6
The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to c
7.5HIGH
CVE-2019-10203
>= 4.0.0 and < 4.0.9
PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between
4.3MEDIUM
CVE-2019-10163
>= 4.0.0 and < 4.0.8
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master
4.3MEDIUM
CVE-2019-10162
>= 4.0.0 and < 4.0.8
A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause
7.5HIGH
CVE-2019-3871
< 4.0.7
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data comin
6.5MEDIUM
CVE-2019-3807
>= 4.1.0 and <= 4.1.8
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received
3.7LOW
CVE-2019-3806
>= 4.1.4 and < 4.1.9
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries
8.1HIGH
CVE-2018-16855
< 4.1.8
An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-o
7.5HIGH
CVE-2018-14626
>= 4.0.0 and <= 4.1.4
PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a pa
5.3MEDIUM
CVE-2018-10851
>= 3.2 and <= 4.1.4
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 a
5.3MEDIUM
CVE-2018-14663
<= 1.3.2
An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such t
5.9MEDIUM
CVE-2018-14644
>= 4.0.0 and <= 4.1.4
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a met
5.3MEDIUM
CVE-2016-2120
<= 3.4.10
An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to
7.5HIGH
CVE-2016-7074
< 4.0.4
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position
5.3MEDIUM
CVE-2016-7073
< 3.7.4
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position
5.3MEDIUM
CVE-2016-7069
<= 1.2.0
An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. Wh
5.9MEDIUM
CVE-2016-7068
< 3.7.4
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unau
5.3MEDIUM
CVE-2016-7072
< 3.4.11
An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to ca
5.3MEDIUM
CVE-2017-15120
< 4.0.8
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer deref
7.5HIGH
CVE-2018-1046
< 4.1.2
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritat
7.8HIGH
CVE-2017-15094
>= 4.0.0 and <= 4.0.6
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory l
5.9MEDIUM
CVE-2017-15093
>= 3.0 and <= 3.7.4
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and incl
5.3MEDIUM
CVE-2017-15092
>= 4.0.0 and <= 4.0.6
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where
6.1MEDIUM
CVE-2017-15091
>= 3.0 and <= 3.4.11
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3
7.1HIGH
CVE-2017-15090
>= 4.0.0 and <= 4.0.6
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where th
5.9MEDIUM
CVE-2018-1000003
all versions
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle posit
3.7LOW
CVE-2017-7557
all versions
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
8.8HIGH
CVE-2016-6172
<= 4.0.0
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhau
6.8MEDIUM
CVE-2016-5427
<= 3.4.9
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attac
7.5HIGH
CVE-2016-5426
<= 3.4.9
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumpti
7.5HIGH
CVE-2015-5311
all versions
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failur
CVE-2015-5470
<= 3.6.3
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server bef
CVE-2015-1868
all versions
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Au
CVE-2014-8601
<= 3.6.1
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("pe
CVE-2014-3614
all versions
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of
CVE-2012-1193
all versions
The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the p
CVE-2012-0206
<= 2.9.22
common_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to caus
CVE-2009-4010
<= 3.1.7.2
Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.
CVE-2009-4009
<= 3.1.7.2
Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibl
CVE-2008-5277
<= 2.9.21.1
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
CVE-2008-3337
<= 2.9.21
PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison D
CVE-2008-3217
<= 3.1.5
PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it
CVE-2008-1637
<= 3.1.4
PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which m
CVE-2006-4252
<= 3.1.3
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application cras
CVE-2006-4251
<= 3.1.3
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP
CVE-2006-2069
all versions
The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0
CVE-2005-0038
<= 2.9.16
The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS pa
CVE-2005-2302
all versions
PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from cli
CVE-2005-2301
all versions
PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to
CVE-2005-0428
all versions
The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sen
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin