Home/Product/powerdns recursor
Product

powerdns recursor

50 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-33601
>= 5.2.0 and < 5.2.9
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null point
4.4MEDIUM
CVE-2026-33600
>= 5.2.0 and < 5.2.9
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check an
4.4MEDIUM
CVE-2026-33262
>= 5.2.0 and < 5.2.9
An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a den
5.9MEDIUM
CVE-2026-33261
>= 5.2.0 and < 5.2.9
A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
5.9MEDIUM
CVE-2026-33260
>= 5.2.0 and < 5.2.9
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of serv
5.3MEDIUM
CVE-2026-33259
>= 5.2.0 and < 5.2.9
Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor.
5.0MEDIUM
CVE-2026-33258
>= 5.2.0 and < 5.2.9
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3)
5.3MEDIUM
CVE-2026-33257
>= 5.2.0 and < 5.2.9
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of serv
5.3MEDIUM
CVE-2026-33256
>= 5.2.0 and < 5.2.9
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of serv
5.3MEDIUM
CVE-2026-24027
>= 5.1.0 and < 5.1.10
Crafted zones can lead to increased incoming network traffic.
5.3MEDIUM
CVE-2026-0398
>= 5.1.0 and < 5.1.10
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
5.3MEDIUM
CVE-2025-59024
>= 5.1.0 and < 5.1.8
Crafted delegations or IP fragments can poison cached delegations in Recursor.
6.5MEDIUM
CVE-2025-59023
>= 5.1.0 and < 5.1.8
Crafted delegations or IP fragments can poison cached delegations in Recursor.
8.2HIGH
CVE-2025-59030
>= 5.1.0 and < 5.1.9
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
7.5HIGH
CVE-2025-59029
all versions
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records c
5.3MEDIUM
CVE-2023-50868
< 4.8.5
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to c
7.5HIGH
CVE-2023-50387
>= 4.8.0 and < 4.8.6
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a den
7.5HIGH
CVE-2023-26437
< 4.6.6
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recu
3.4LOW
CVE-2023-22617
all versions
A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records f
7.5HIGH
CVE-2022-37428
>= 4.5.0 and < 4.5.10
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown
6.5MEDIUM
CVE-2022-27227
< 4.4.8
In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.
7.5HIGH
CVE-2020-25829
< 4.1.18
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can caus
7.5HIGH
CVE-2020-14196
<= 4.1.16
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server i
5.3MEDIUM
CVE-2020-10995
>= 4.1.0 and <= 4.3.0
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the
7.5HIGH
CVE-2020-10030
>= 4.1.0 and <= 4.3.0
An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to cha
8.8HIGH
CVE-2020-12244
>= 4.1.0 and <= 4.3.0
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lackin
7.5HIGH
CVE-2019-3807
>= 4.1.0 and <= 4.1.8
An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received
3.7LOW
CVE-2019-3806
>= 4.1.4 and < 4.1.9
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries
8.1HIGH
CVE-2018-16855
< 4.1.8
An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-o
7.5HIGH
CVE-2018-14626
>= 4.0.0 and <= 4.1.4
PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a pa
5.3MEDIUM
CVE-2018-10851
>= 3.2 and <= 4.1.4
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 a
5.3MEDIUM
CVE-2018-14644
>= 4.0.0 and <= 4.1.4
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a met
5.3MEDIUM
CVE-2016-7074
< 4.0.4
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position
5.3MEDIUM
CVE-2016-7073
< 3.7.4
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position
5.3MEDIUM
CVE-2016-7068
< 3.7.4
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unau
5.3MEDIUM
CVE-2017-15120
< 4.0.8
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer deref
7.5HIGH
CVE-2017-15094
>= 4.0.0 and <= 4.0.6
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory l
5.9MEDIUM
CVE-2017-15093
>= 3.0 and <= 3.7.4
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and incl
5.3MEDIUM
CVE-2017-15092
>= 4.0.0 and <= 4.0.6
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where
6.1MEDIUM
CVE-2017-15090
>= 4.0.0 and <= 4.0.6
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where th
5.9MEDIUM
CVE-2018-1000003
all versions
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle posit
3.7LOW
CVE-2015-5470
<= 3.6.3
The label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server bef
CVE-2015-1868
all versions
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Au
CVE-2014-8601
<= 3.6.1
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("pe
CVE-2009-4010
<= 3.1.7.2
Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.
CVE-2009-4009
<= 3.1.7.2
Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibl
CVE-2008-3217
<= 3.1.5
PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it
CVE-2008-1637
<= 3.1.4
PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which m
CVE-2006-4252
<= 3.1.3
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application cras
CVE-2006-4251
<= 3.1.3
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin