Where
-Infinity
0

It has been brought to our attention that the CVE number of the second issue is wrong. It should be CVE-2026-52686.

Regards, Otto On 22/07/2026 13:54 CEST Otto Moerbeek <otto.moerbeek () powerdns com> wrote:

Today we have released PowerDNS Recursor 5.2.12, 5.3.9 and 5.4.4.

These releases provide fixes for PowerDNS Security Advisory

2026-10 for PowerDNS Recursor: Multiple issues

There are two CVEs associated with this advisory, one with severity High and one with severity Low.

CVE-2026-52688: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation CVE-2026-62686: Wildcard CNAME proof validation bypass

Please refer to the changelogs ([1]5.2.12, [2]5.3.9 and [3]5.4.4) and the full [4]security advisory for additional details.

Please send us all feedback and issues you might have via the [5]mailing list, or in case of a bug, via [6]GitHub.

The tarballs ([7]5.2.12, [8]5.3.9, [9]5.4.4) (with signature files [10]5.2.12, [11]5.3.9, [12]5.4.4) are available from our download [13]server and packages for several distributions are available from our [14]repository.

Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL [15]policy for more details.

We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.

References

1. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.12 2. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.9 3. https://doc.powerdns.com/recursor/changelog/5.4.html#change-5.4.4 4. https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-10.html 5. https://mailman.powerdns.com/mailman/listinfo/pdns-users 6. https://github.com/PowerDNS/pdns/issues/new/choose 7. https://downloads.powerdns.com/releases/pdns-recursor-5.2.12.tar.bz2 8. https://downloads.powerdns.com/releases/pdns-recursor-5.3.9.tar.xz 9. https://downloads.powerdns.com/releases/pdns-recursor-5.4.4.tar.xz 10. https://downloads.powerdns.com/releases/pdns-recursor-5.2.12.tar.bz2.sig 11. https://downloads.powerdns.com/releases/pdns-recursor-5.3.9.tar.xz.sig 12. https://downloads.powerdns.com/releases/pdns-recursor-5.4.4.tar.xz.sig 13. https://downloads.powerdns.com/releases/ 14. https://repo.powerdns.com/ 15. https://docs.powerdns.com/recursor/appendices/EOL.html --

kind regards, Otto Moerbeek Developer PowerDNS

Phone: +49 2761 75252 00 Fax: +49 2761 75252 30 Email: otto.moerbeek () powerdns com

------------------------------------------------------------------------------------- Open-Xchange AG, Hohenzollernring 72, 50672 Cologne, District Court Cologne HRB 95366 Managing Board: Andreas Gauger, Dirk Valbert Chairman of the Board: Dr. Paul-Josef Patt

PowerDNS.com B.V., Koninginnegracht 5, 2514 AA Den Haag, The Netherlands Managing Director: Robert Brandt -------------------------------------------------------------------------------------

Today we have released PowerDNS Recursor 5.2.12, 5.3.9 and 5.4.4.

These releases provide fixes for PowerDNS Security Advisory

2026-10 for PowerDNS Recursor: Multiple issues

There are two CVEs associated with this advisory, one with severity High and one with severity Low.

CVE-2026-52688: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation CVE-2026-62686: Wildcard CNAME proof validation bypass

Please refer to the changelogs ([1]5.2.12, [2]5.3.9 and [3]5.4.4) and the full [4]security advisory for additional details.

Please send us all feedback and issues you might have via the [5]mailing list, or in case of a bug, via [6]GitHub.

The tarballs ([7]5.2.12, [8]5.3.9, [9]5.4.4) (with signature files [10]5.2.12, [11]5.3.9, [12]5.4.4) are available from our download [13]server and packages for several distributions are available from our [14]repository.

Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL [15]policy for more details.

We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.

References

1. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.12 2. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.9 3. https://doc.powerdns.com/recursor/changelog/5.4.html#change-5.4.4 4. https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-10.html 5. https://mailman.powerdns.com/mailman/listinfo/pdns-users 6. https://github.com/PowerDNS/pdns/issues/new/choose 7. https://downloads.powerdns.com/releases/pdns-recursor-5.2.12.tar.bz2 8. https://downloads.powerdns.com/releases/pdns-recursor-5.3.9.tar.xz 9. https://downloads.powerdns.com/releases/pdns-recursor-5.4.4.tar.xz 10. https://downloads.powerdns.com/releases/pdns-recursor-5.2.12.tar.bz2.sig 11. https://downloads.powerdns.com/releases/pdns-recursor-5.3.9.tar.xz.sig 12. https://downloads.powerdns.com/releases/pdns-recursor-5.4.4.tar.xz.sig 13. https://downloads.powerdns.com/releases/ 14. https://repo.powerdns.com/ 15. https://docs.powerdns.com/recursor/appendices/EOL.html

Today we have released PowerDNS Recursor 5.2.11, 5.3.8 and 5.4.3.

These releases provide fixes for PowerDNS Security Advisory

2026-08 for PowerDNS Recursor: Multiple issues

There are several CVEs associated with this advisory, the first with severity High (but only applicable to specific configurations), the rest of severity Medium.

CVE-2026-33612: ZoneToCache can poison the cache CVE-2026-40012: Information about ECS zero scoped answers might leak to clients that use a specific ECS CVE-2026-42005: Unbounded resource consumption in internal webserver CVE-2026-42390: ZONEMD validation can be bypassed CVE-2026-42389: Reject more queries with invalid header values CVE-2026-42388: Missing input validation for catalog zones CVE-2026-42387: Insufficient input validation in ZoneToCache CVE-2026-52690: Spoofed answers can mark an authoritative non-EDNS capable

Please refer to the changelogs ([1]5.2.11, [2]5.3.8 and [3]5.4.3) and the full [4]security advisory for additional details.

Please send us all feedback and issues you might have via the [5]mailing list, or in case of a bug, via [6]GitHub.

The tarballs ([7]5.2.11, [8]5.3.8, [9]5.4.3) (with signature files [10]5.2.11, [11]5.3.8, [12]5.4.3) are available from our download [13]server and packages for several distributions are available from our [14]repository.

Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL [15]policy for more details.

We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.

References

1. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.11 2. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.8 3. https://doc.powerdns.com/recursor/changelog/5.4.html#change-5.4.3 4. https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-08.html 5. https://mailman.powerdns.com/mailman/listinfo/pdns-users 6. https://github.com/PowerDNS/pdns/issues/new/choose 7. https://downloads.powerdns.com/releases/pdns-recursor-5.2.11.tar.bz2 8. https://downloads.powerdns.com/releases/pdns-recursor-5.3.8.tar.xz 9. https://downloads.powerdns.com/releases/pdns-recursor-5.4.3.tar.xz 10. https://downloads.powerdns.com/releases/pdns-recursor-5.2.11.tar.bz2.sig 11. https://downloads.powerdns.com/releases/pdns-recursor-5.3.8.tar.xz.sig 12. https://downloads.powerdns.com/releases/pdns-recursor-5.4.3.tar.xz.sig 13. https://downloads.powerdns.com/releases/ 14. https://repo.powerdns.com/ 15. https://docs.powerdns.com/recursor/appendices/EOL.html

We have released PowerDNS Recursor 5.2.9, 5.3.6 and 5.4.1.

These releases provide fixes for PowerDNS Security Advisory

2026-03 for PowerDNS Recursor: Multiple issues

There are several CVEs associated with this advisory, all of severity Medium.

CVE-2026-33256 Unbounded memory allocation by internal web server, affected 5.3.5, 5.4.0 CVE-2026-33257 Insufficient input validation of internal web server, affected 5.2.8 CVE-2026-33258 Crafted zones can cause increased resource usage, affected 5.2.8, 5.3.5, 5.4.0 CVE-2026-33259 Concurrent modification of RPZ data can lead to denial of service, affected 5.2.8 5.3.5, 5.4.0 CVE-2026-33260 Insufficient input validation of internal web server, affected 5.2.8 CVE-2026-33261 Null pointer access in aggressive NSEC(3) cache, affected 5.2.8, 5.3.5, 5.4.0 CVE-2026-33262 Insufficient validation of cookie reply, affected 5.4.0 CVE-2026-33601 Insufficient validation of ZONEMD record, affected 5.2.8, 5.3.5, 5.4.0 CVE-2026-33600 Null pointer dereference in RPZ transfer, affected 5.2.8, 5.3.5, 5.4.0

Please refer to the changelogs (5.2.9[1], 5.3.6[2] and 5.4.1[3]) and the full security advisory[4] for additional details.

Please send us all feedback and issues you might have via the mailing list[5], or in case of a bug, via GitHub[6].

The tarballs (5.2.9[7], 5.3.6[8], 5.4.1[9]) (with signature files 5.2.9[10], 5.3.6[11], 5.4.1[12]) are available from our download server[13] and packages for several distributions are available from our repository[14].

Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL policy[15] for more details.

We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.

References

1. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.9 2. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.6 3. https://doc.powerdns.com/recursor/changelog/5.4.html#change-5.4.1 4. https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-03.html 5. https://mailman.powerdns.com/mailman/listinfo/pdns-users 6. https://github.com/PowerDNS/pdns/issues/new/choose 7. https://downloads.powerdns.com/releases/pdns-recursor-5.2.9.tar.bz2 8. https://downloads.powerdns.com/releases/pdns-recursor-5.3.6.tar.xz 9. https://downloads.powerdns.com/releases/pdns-recursor-5.4.1.tar.xz 10. https://downloads.powerdns.com/releases/pdns-recursor-5.2.9.tar.bz2.sig 11. https://downloads.powerdns.com/releases/pdns-recursor-5.3.6.tar.xz.sig 12. https://downloads.powerdns.com/releases/pdns-recursor-5.4.1.tar.xz.sig 13. https://downloads.powerdns.com/releases/ 14. https://repo.powerdns.com/ 15. https://docs.powerdns.com/recursor/appendices/EOL.html

Today we have released PowerDNS Recursor 5.1.9, 5.2.7 and 5.3.3.

These releases fix two PowerDNS Security Advisories:

2025-07: Internal logic flaw in cache management can lead to a denial of service in Recursor 2025-08: Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor.

PowerDNS Security Advisory 2025-07: Internal logic flaw in cache management can lead to a denial of service in Recursor

CVE: CVE-2025-59029 Date: 8th December 2025 Affects: PowerDNS Recursor 5.3.0 and 5.3.1 Not affected: PowerDNS Recursor 5.1.x, 5.2.x and 5.3.2 Severity: Medium Impact: Denial of Service Exploit: This problem can be triggered by specific cache contents and a query with qtype ANY Risk of system compromise: None Solution: Upgrade to patched version or prevent requests with qtype ANY

CVSS Score: 5.6, see https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/P R:N/UI:N/S:U/C:N/I:N/A:L&version=3.1[1]

The remedy is: upgrade to a patched version or prevent requests with qtype ANY.

Version 5.3.2 of PowerDNS Recursor was never released publicly, upgrade to version 5.3.3.

PowerDNS Security Advisory 2025-08: Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor

CVE: CVE-2025-59030 Date: 8th December 2025 Affects: PowerDNS Recursor up to and including 5.3.2, 5.2.6 and 5.1.8 Not affected: PowerDNS Recursor 5.3.3, 5.2.7 and 5.1.9 Severity: High Impact: Denial of Service Exploit: This problem can be triggered by a notify arriving over TCP and allows clearing caches Risk of system compromise: None Solution: Upgrade to patched version or prevent incoming notifies over TCP

CVSS Score: 7.5, see https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/P R:N/UI:N/S:U/C:N/I:N/A:H&version=3.1[2]

The remedy is: upgrade to patched version or prevent incoming notifies over TCP.

Please refer to the changelogs (5.1.9[3], 5.2.7[4] and 5.3.3[5]) for additional details

Please send us all feedback and issues you might have via the mailing list[6], or in case of a bug, via GitHub[7].

The tarballs (5.1.9[8], 5.2.7[9], 5.3.3[10]) (with signature files 5.1.9[11], 5.2.7[12], 5.3.3[13]) are available from our download server[14] and packages for several distributions are available from our repository[15].

Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL policy[16] for more details.

We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.

References

1. https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1 2. https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H&version=3.1 3. https://doc.powerdns.com/recursor/changelog/5.1.html#change-5.1.9 4. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.7 5. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.3 6. https://mailman.powerdns.com/mailman/listinfo/pdns-users 7. https://github.com/PowerDNS/pdns/issues/new/choose 8. https://downloads.powerdns.com/releases/pdns-recursor-5.1.9.tar.bz2 9. https://downloads.powerdns.com/releases/pdns-recursor-5.2.7.tar.bz2 10. https://downloads.powerdns.com/releases/pdns-recursor-5.3.3.tar.xz 11. https://downloads.powerdns.com/releases/pdns-recursor-5.1.9.tar.bz2.sig 12. https://downloads.powerdns.com/releases/pdns-recursor-5.2.7.tar.bz2.sig 13. https://downloads.powerdns.com/releases/pdns-recursor-5.3.3.tar.xz.sig 14. https://downloads.powerdns.com/releases/ 15. https://repo.powerdns.com/ 16. https://docs.powerdns.com/recursor/appendices/EOL.html

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203