Where
-Infinity
0

Today we have released PowerDNS Authoritative Server 4.9.17, 5.0.7, 5.1.4, Recursor 5.2.13, 5.3.10, 5.4.5, and dnsdist 1.9.16, 2.0.8, 2.1.1.

These releases provide fixes for PowerDNS Security Advisory

2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumption

The CVE associated with this advisory is of severity High.

CVE-2026-52682: A crafted DNS packet can cause increased memory and CPU consumption

Please refer to the changelogs for Authoritative Server ([1]4.9.17, [2]5.0.7, [3]5.1.4), Recursor ([4]5.2.13, [5]5.3.10 and [6]5.4.5) and dnsdist ([7]1.9.16, [8]2.0.8, [9]2.1.1) and the full [10]security advisory for additional details.

Please send us all feedback and issues you might have via the [11]mailing list, or in case of a bug, via [12]GitHub.

The tarballs for Authoritative Server ([13]4.9.17, [14]5.0.7, [15]5.1.4 with signature files [16]4.9.17, [17]5.0.7, [18]5.1.4), Recursor ([19]5.2.13, [20]5.3.10, [21]5.4.5 with signature files [22]5.2.13, [23]5.3.10, [24]5.4.5) and dnsdist ([25]1.9.16, [26]2.0.8, [27]2.1.1 with signature files [28]1.9.16, [29]2.0.8, [30]2.1.1) are available from our download [31]server and packages for several distributions are available from our [32]repository.

Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL [33]policy for more details.

We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.

References

1. https://docs.powerdns.com/authoritative/changelog/4.9.html#change-4.9.17 2. https://docs.powerdns.com/authoritative/changelog/5.0.html#change-5.0.7 3. https://docs.powerdns.com/authoritative/changelog/5.1.html#change-5.1.4 4. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.13 5. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.10 6. https://doc.powerdns.com/recursor/changelog/5.4.html#change-5.4.5 7. https://www.dnsdist.org/changelog.html#change-1.9.16 8. https://www.dnsdist.org/changelog.html#change-2.0.8 9. https://www.dnsdist.org/changelog.html#change-2.1.1 10. https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-11.html 11. https://mailman.powerdns.com/mailman/listinfo/pdns-users 12. https://github.com/PowerDNS/pdns/issues/new/choose 13. https://downloads.powerdns.com/releases/pdns-4.9.17.tar.bz2 14. https://downloads.powerdns.com/releases/pdns-5.0.7.tar.bz2 15. https://downloads.powerdns.com/releases/pdns-5.1.4.tar.bz2 16. https://downloads.powerdns.com/releases/pdns-4.9.17.tar.bz2.sig 17. https://downloads.powerdns.com/releases/pdns-5.0.7.tar.bz2.sig 18. https://downloads.powerdns.com/releases/pdns-5.1.4.tar.bz2.sig 19. https://downloads.powerdns.com/releases/pdns-recursor-5.2.13.tar.bz2 20. https://downloads.powerdns.com/releases/pdns-recursor-5.3.10.tar.xz 21. https://downloads.powerdns.com/releases/pdns-recursor-5.4.5.tar.xz 22. https://downloads.powerdns.com/releases/pdns-recursor-5.2.13.tar.bz2.sig 23. https://downloads.powerdns.com/releases/pdns-recursor-5.3.10.tar.xz.sig 24. https://downloads.powerdns.com/releases/pdns-recursor-5.4.5.tar.xz.sig 25. https://downloads.powerdns.com/releases/dnsdist-1.9.16.tar.bz2 26. https://downloads.powerdns.com/releases/dnsdist-2.0.8.tar.xz 27. https://downloads.powerdns.com/releases/dnsdist-2.1.1.tar.xz 28. https://downloads.powerdns.com/releases/dnsdist-1.9.16.tar.bz2.sig 29. https://downloads.powerdns.com/releases/dnsdist-2.0.8.tar.xz.sig 30. https://downloads.powerdns.com/releases/dnsdist-2.1.1.tar.xz.sig 31. https://downloads.powerdns.com/releases/ 32. https://repo.powerdns.com/ 33. https://docs.powerdns.com/recursor/appendices/EOL.html

--

kind regards, Otto Moerbeek Developer PowerDNS

Phone: +49 2761 75252 00 Fax: +49 2761 75252 30 Email: otto.moerbeek () powerdns com

------------------------------------------------------------------------------------- Open-Xchange AG, Hohenzollernring 72, 50672 Cologne, District Court Cologne HRB 95366 Managing Board: Andreas Gauger, Dirk Valbert Chairman of the Board: Dr. Paul-Josef Patt

PowerDNS.com B.V., Koninginnegracht 5, 2514 AA Den Haag, The Netherlands Managing Director: Robert Brandt -------------------------------------------------------------------------------------

Severity
5.9
Null Pointer Dereference
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.

First published (updated )
Severity
5.9
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

First published (updated )
Severity
5
Use After Free
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H

Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

First published (updated )
Severity
4.9
Null Pointer Dereference
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

First published (updated )
Severity
4.9
Null Pointer Dereference
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

First published (updated )

We have released PowerDNS Recursor 5.1.10, 5.2.8 and 5.3.5.

These releases fix a PowerDNS Security Advisory

2026-01: Crafted zones can lead to increased resource usage in Recursor

There are two CVEs associated with this advisory, both of severity Medium.

CVE: CVE-2026-24027 Date: 9th February 2026 Affects: PowerDNS Recursor up and including to 5.1.9, 5.2.7 and 5.3.4 Not affected: PowerDNS Recursor 5.1.10, 5.2.8 and 5.3.5 Severity: Medium Impact: Denial of Service Exploit: This problem can be triggered by publishing and querying a crafted zone that causes increased incoming network traffic. Risk of system compromise: None Solution: Upgrade to patched version

CVSS Score: 5.3, see https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/P R:N/UI:N/S:U/C:N/I:N/A:L&version=3.1[1]

The remedy is: upgrade to a patched version.

We would like to thank Shuhan Zhang from Tsinghua University for bringing this issue to our attention. CVE: CVE-2026-0398 Date: 9th February 2026 Affects: PowerDNS Recursor up and including to 5.1.9, 5.2.7 and 5.3.4 Not affected: PowerDNS Recursor 5.1.10, 5.2.8 and 5.3.5 Severity: Medium Impact: Denial of Service Exploit: This problem can be triggered by publishing and querying a crafted zone that causes large memory usage. Risk of system compromise: None Solution: Upgrade to patched version

CVSS Score: 5.3, see https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/P R:N/UI:N/S:U/C:N/I:N/A:L&version=3.1[2]

The remedy is: upgrade to a patched version.

We would like to thank Yufan You from Tsinghua University for bringing this issue to our attention.

We would also like to thank TaoFei Guo from Peking University and Yang Luo, JianJun Chen from Tsinghua University for bringing an issue of caching irrelevant records related to CNAME chains to our attention.

Please refer to the changelogs (5.1.10[3], 5.2.8[4] and 5.3.5[5]) for additional details

Please send us all feedback and issues you might have via the mailing list[6], or in case of a bug, via GitHub[7].

The tarballs (5.1.10[8], 5.2.8[9], 5.3.5[10]) (with signature files 5.1.10[11], 5.2.8[12], 5.3.5[13]) are available from our download server[14] and packages for several distributions are available from our repository[15].

At the moment of writing, the patches[16] are not incorporated yet in the public github repository. There has been a delay in the process to transfer them from our private repository (where they were developed) to the public repository.

Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL policy[17] for more details.

We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.

References

1. https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1 2. https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1 3. https://doc.powerdns.com/recursor/changelog/5.1.html#change-5.1.10 4. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.8 5. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.5 6. https://mailman.powerdns.com/mailman/listinfo/pdns-users 7. https://github.com/PowerDNS/pdns/issues/new/choose 8. https://downloads.powerdns.com/releases/pdns-recursor-5.1.10.tar.bz2 9. https://downloads.powerdns.com/releases/pdns-recursor-5.2.8.tar.bz2 10. https://downloads.powerdns.com/releases/pdns-recursor-5.3.5.tar.xz 11. https://downloads.powerdns.com/releases/pdns-recursor-5.1.10.tar.bz2.sig 12. https://downloads.powerdns.com/releases/pdns-recursor-5.2.8.tar.bz2.sig 13. https://downloads.powerdns.com/releases/pdns-recursor-5.3.5.tar.xz.sig 14. https://downloads.powerdns.com/releases/ 15. https://repo.powerdns.com/ 16. https://downloads.powerdns.com/patches/2026-01/ 17. https://docs.powerdns.com/recursor/appendices/EOL.html

Severity
6.5
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L

Crafted delegations or IP fragments can poison cached delegations in Recursor.

First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Crafted delegations or IP fragments can poison cached delegations in Recursor.

First published (updated )
Severity
5.3
EPSS
0.01%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Crafted zones can lead to increased incoming network traffic.

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

ISC BIND is vulnerable to a denial of service, caused by an error when preparing an NSEC3 closest encloser proof. By flooding the target resolver with queries, a remote attacker could exploit this vulnerability to cause CPU exhaustion on a DNSSEC-validating resolver.

1 / 5
Source: IBM
First published (updated )
Severity
7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C

The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.

First published (updated )
Severity
5
AV:N/AC:L/Au:N/C:N/I:N/A:P

PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.

First published (updated )
Severity
7.5
Buffer Overflow
AV:N/AC:L/Au:N/C:P/I:P/A:P

Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203