Today we have released PowerDNS Authoritative Server 4.9.17, 5.0.7, 5.1.4, Recursor 5.2.13, 5.3.10, 5.4.5, and dnsdist 1.9.16, 2.0.8, 2.1.1.
These releases provide fixes for PowerDNS Security Advisory
2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumption
The CVE associated with this advisory is of severity High.
CVE-2026-52682: A crafted DNS packet can cause increased memory and CPU consumption
Please refer to the changelogs for Authoritative Server ([1]4.9.17, [2]5.0.7, [3]5.1.4), Recursor ([4]5.2.13, [5]5.3.10 and [6]5.4.5) and dnsdist ([7]1.9.16, [8]2.0.8, [9]2.1.1) and the full [10]security advisory for additional details.
Please send us all feedback and issues you might have via the [11]mailing list, or in case of a bug, via [12]GitHub.
The tarballs for Authoritative Server ([13]4.9.17, [14]5.0.7, [15]5.1.4 with signature files [16]4.9.17, [17]5.0.7, [18]5.1.4), Recursor ([19]5.2.13, [20]5.3.10, [21]5.4.5 with signature files [22]5.2.13, [23]5.3.10, [24]5.4.5) and dnsdist ([25]1.9.16, [26]2.0.8, [27]2.1.1 with signature files [28]1.9.16, [29]2.0.8, [30]2.1.1) are available from our download [31]server and packages for several distributions are available from our [32]repository.
Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL [33]policy for more details.
We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.
References
1. https://docs.powerdns.com/authoritative/changelog/4.9.html#change-4.9.17 2. https://docs.powerdns.com/authoritative/changelog/5.0.html#change-5.0.7 3. https://docs.powerdns.com/authoritative/changelog/5.1.html#change-5.1.4 4. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.13 5. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.10 6. https://doc.powerdns.com/recursor/changelog/5.4.html#change-5.4.5 7. https://www.dnsdist.org/changelog.html#change-1.9.16 8. https://www.dnsdist.org/changelog.html#change-2.0.8 9. https://www.dnsdist.org/changelog.html#change-2.1.1 10. https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-11.html 11. https://mailman.powerdns.com/mailman/listinfo/pdns-users 12. https://github.com/PowerDNS/pdns/issues/new/choose 13. https://downloads.powerdns.com/releases/pdns-4.9.17.tar.bz2 14. https://downloads.powerdns.com/releases/pdns-5.0.7.tar.bz2 15. https://downloads.powerdns.com/releases/pdns-5.1.4.tar.bz2 16. https://downloads.powerdns.com/releases/pdns-4.9.17.tar.bz2.sig 17. https://downloads.powerdns.com/releases/pdns-5.0.7.tar.bz2.sig 18. https://downloads.powerdns.com/releases/pdns-5.1.4.tar.bz2.sig 19. https://downloads.powerdns.com/releases/pdns-recursor-5.2.13.tar.bz2 20. https://downloads.powerdns.com/releases/pdns-recursor-5.3.10.tar.xz 21. https://downloads.powerdns.com/releases/pdns-recursor-5.4.5.tar.xz 22. https://downloads.powerdns.com/releases/pdns-recursor-5.2.13.tar.bz2.sig 23. https://downloads.powerdns.com/releases/pdns-recursor-5.3.10.tar.xz.sig 24. https://downloads.powerdns.com/releases/pdns-recursor-5.4.5.tar.xz.sig 25. https://downloads.powerdns.com/releases/dnsdist-1.9.16.tar.bz2 26. https://downloads.powerdns.com/releases/dnsdist-2.0.8.tar.xz 27. https://downloads.powerdns.com/releases/dnsdist-2.1.1.tar.xz 28. https://downloads.powerdns.com/releases/dnsdist-1.9.16.tar.bz2.sig 29. https://downloads.powerdns.com/releases/dnsdist-2.0.8.tar.xz.sig 30. https://downloads.powerdns.com/releases/dnsdist-2.1.1.tar.xz.sig 31. https://downloads.powerdns.com/releases/ 32. https://repo.powerdns.com/ 33. https://docs.powerdns.com/recursor/appendices/EOL.html
--
kind regards, Otto Moerbeek Developer PowerDNS
Phone: +49 2761 75252 00 Fax: +49 2761 75252 30 Email: otto.moerbeek () powerdns com
------------------------------------------------------------------------------------- Open-Xchange AG, Hohenzollernring 72, 50672 Cologne, District Court Cologne HRB 95366 Managing Board: Andreas Gauger, Dirk Valbert Chairman of the Board: Dr. Paul-Josef Patt
PowerDNS.com B.V., Koninginnegracht 5, 2514 AA Den Haag, The Netherlands Managing Director: Robert Brandt -------------------------------------------------------------------------------------
An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.
A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
We have released PowerDNS Recursor 5.1.10, 5.2.8 and 5.3.5.
These releases fix a PowerDNS Security Advisory
2026-01: Crafted zones can lead to increased resource usage in Recursor
There are two CVEs associated with this advisory, both of severity Medium.
CVE: CVE-2026-24027 Date: 9th February 2026 Affects: PowerDNS Recursor up and including to 5.1.9, 5.2.7 and 5.3.4 Not affected: PowerDNS Recursor 5.1.10, 5.2.8 and 5.3.5 Severity: Medium Impact: Denial of Service Exploit: This problem can be triggered by publishing and querying a crafted zone that causes increased incoming network traffic. Risk of system compromise: None Solution: Upgrade to patched version
CVSS Score: 5.3, see https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/P R:N/UI:N/S:U/C:N/I:N/A:L&version=3.1[1]
The remedy is: upgrade to a patched version.
We would like to thank Shuhan Zhang from Tsinghua University for bringing this issue to our attention. CVE: CVE-2026-0398 Date: 9th February 2026 Affects: PowerDNS Recursor up and including to 5.1.9, 5.2.7 and 5.3.4 Not affected: PowerDNS Recursor 5.1.10, 5.2.8 and 5.3.5 Severity: Medium Impact: Denial of Service Exploit: This problem can be triggered by publishing and querying a crafted zone that causes large memory usage. Risk of system compromise: None Solution: Upgrade to patched version
CVSS Score: 5.3, see https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/P R:N/UI:N/S:U/C:N/I:N/A:L&version=3.1[2]
The remedy is: upgrade to a patched version.
We would like to thank Yufan You from Tsinghua University for bringing this issue to our attention.
We would also like to thank TaoFei Guo from Peking University and Yang Luo, JianJun Chen from Tsinghua University for bringing an issue of caching irrelevant records related to CNAME chains to our attention.
Please refer to the changelogs (5.1.10[3], 5.2.8[4] and 5.3.5[5]) for additional details
Please send us all feedback and issues you might have via the mailing list[6], or in case of a bug, via GitHub[7].
The tarballs (5.1.10[8], 5.2.8[9], 5.3.5[10]) (with signature files 5.1.10[11], 5.2.8[12], 5.3.5[13]) are available from our download server[14] and packages for several distributions are available from our repository[15].
At the moment of writing, the patches[16] are not incorporated yet in the public github repository. There has been a delay in the process to transfer them from our private repository (where they were developed) to the public repository.
Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL policy[17] for more details.
We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.
References
1. https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1 2. https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1 3. https://doc.powerdns.com/recursor/changelog/5.1.html#change-5.1.10 4. https://doc.powerdns.com/recursor/changelog/5.2.html#change-5.2.8 5. https://doc.powerdns.com/recursor/changelog/5.3.html#change-5.3.5 6. https://mailman.powerdns.com/mailman/listinfo/pdns-users 7. https://github.com/PowerDNS/pdns/issues/new/choose 8. https://downloads.powerdns.com/releases/pdns-recursor-5.1.10.tar.bz2 9. https://downloads.powerdns.com/releases/pdns-recursor-5.2.8.tar.bz2 10. https://downloads.powerdns.com/releases/pdns-recursor-5.3.5.tar.xz 11. https://downloads.powerdns.com/releases/pdns-recursor-5.1.10.tar.bz2.sig 12. https://downloads.powerdns.com/releases/pdns-recursor-5.2.8.tar.bz2.sig 13. https://downloads.powerdns.com/releases/pdns-recursor-5.3.5.tar.xz.sig 14. https://downloads.powerdns.com/releases/ 15. https://repo.powerdns.com/ 16. https://downloads.powerdns.com/patches/2026-01/ 17. https://docs.powerdns.com/recursor/appendices/EOL.html
Crafted delegations or IP fragments can poison cached delegations in Recursor.
Crafted delegations or IP fragments can poison cached delegations in Recursor.
Crafted zones can lead to increased incoming network traffic.
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
ISC BIND is vulnerable to a denial of service, caused by an error when preparing an NSEC3 closest encloser proof. By flooding the target resolver with queries, a remote attacker could exploit this vulnerability to cause CPU exhaustion on a DNSSEC-validating resolver.
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.
Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length.