MEDIUM

CVE-2026-42387

2026-06-25 CVSS v3.1
CVSS
5.9

Description

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.

Summary dbcve.org

A vulnerability in PowerDNS Recursor's ZoneToCache function allows a malicious authoritative server to send a specially crafted zone that causes the Recursor to crash due to insufficient input validation. An attacker controlling an authoritative server can exploit this by serving malformed zone data to vulnerable Recursor instances.

Mitigation

Upgrade to patched versions when available, and restrict which authoritative servers can provide zones to the Recursor through access controls.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

0.39%
Probability of exploitation in next 30 days
32.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE