Powerdns
Powerdns Recursor: vulnerabilidades y CVE
Powerdns Recursor tiene 54 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE54
Últimos 12 meses16
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-42387 | Media (5.9) | 0.48% | — | 25 jun 2026 | A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation. |
| CVE-2026-33601 | Media (4.9) | 0.72% | — | 22 abr 2026 | If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. |
| CVE-2026-33600 | Media (4.9) | 0.72% | — | 22 abr 2026 | An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. |
| CVE-2026-33262 | Media (5.9) | 0.46% | — | 22 abr 2026 | An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default. |
| CVE-2026-33261 | Media (5.9) | 0.23% | — | 22 abr 2026 | A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service. |
| CVE-2026-33260 | Alta (7.5) | 1.1% | — | 22 abr 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. |
| CVE-2026-33259 | Media (5) | 0.27% | — | 22 abr 2026 | Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning… |
| CVE-2026-33258 | Alta (7.5) | 0.80% | — | 22 abr 2026 | By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches. |
| CVE-2026-33257 | Alta (7.5) | 1.1% | — | 22 abr 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. |
| CVE-2026-33256 | Alta (7.5) | 0.80% | — | 22 abr 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. |
| CVE-2026-24027 | Media (5.3) | 0.42% | — | 9 feb 2026 | Crafted zones can lead to increased incoming network traffic. |
| CVE-2026-0398 | Media (5.3) | 0.32% | — | 9 feb 2026 | Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor. |
| CVE-2025-59024 | Media (6.5) | 0.13% | — | 9 feb 2026 | Crafted delegations or IP fragments can poison cached delegations in Recursor. |
| CVE-2025-59023 | Alta (8.2) | 0.28% | — | 9 feb 2026 | Crafted delegations or IP fragments can poison cached delegations in Recursor. |
| CVE-2025-59030 | Alta (7.5) | 0.58% | — | 9 dic 2025 | An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP. |
| CVE-2025-59029 | Media (5.3) | 0.37% | — | 9 dic 2025 | An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY. |
| CVE-2025-30192 | Alta (7.5) | 0.24% | — | 21 jul 2025 | An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS… |
| CVE-2025-30195 | Alta (7.5) | 0.76% | — | 7 abr 2025 | An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The… |
| CVE-2024-25583 | Alta (7.5) | 0.83% | — | 25 abr 2024 | A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive… |
| CVE-2023-50868 | Alta (7.5) | 74% | — | 14 feb 2024 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in… |
| CVE-2023-50387 | Alta (7.5) | 100% | — | 14 feb 2024 | Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap"… |
| CVE-2023-26437 | Media (5.3) | 0.59% | — | 4 abr 2023 | Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3. |
| CVE-2023-22617 | Alta (7.5) | 7.3% | — | 21 ene 2023 | A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured domain, because QName minimization is used in QM fallback mode. This… |
| CVE-2022-37428 | Media (6.5) | 1.4% | — | 23 ago 2022 | PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to… |
| CVE-2022-27227 | Alta (7.5) | 5.0% | — | 25 mar 2022 | In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition… |
| CVE-2020-25829 | Alta (7.5) | 6.5% | — | 16 oct 2020 | An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached records for a given name to be updated to the Bogus DNSSEC validation state,… |
| CVE-2020-14196 | Media (5.3) | 1.7% | — | 1 jul 2020 | In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced. |
| CVE-2020-10995 | Alta (7.5) | 4.4% | — | 19 may 2020 | PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services… |
| CVE-2020-10030 | Alta (8.8) | 24% | — | 19 may 2020 | An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's hostname) to cause disclosure of uninitialized memory content via a… |
| CVE-2020-12244 | Alta (7.5) | 2.4% | — | 19 may 2020 | An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.