CVE-2026-42389: Reject more queries with invalid header values
Published Jun 25, 2026
·Updated
This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.
Affected Software
1 affected component
Unknown Unknown
Event History
Jun 25, 2026
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42389?
CVE-2026-42389 has a medium severity rating of 5.3, indicating a moderate level of risk.
2
How do I fix CVE-2026-42389?
Fixing CVE-2026-42389 requires applying the latest updates that include enhanced validation for incoming answers from authoritative servers.
3
What types of systems are affected by CVE-2026-42389?
CVE-2026-42389 impacts systems using the affected versions of PowerDNS, particularly within the 5.4.x branch.
4
What does CVE-2026-42389 address specifically?
CVE-2026-42389 addresses the issue of accepting queries with invalid header values by implementing stricter validation.
5
When was CVE-2026-42389 published?
CVE-2026-42389 was published on June 25, 2026.