MEDIUM
CVE-2026-52690
CVSS
5.9
Description
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.
Summary dbcve.org
A spoofing vulnerability in DNS Recursor allows attackers to send伪造 replies that incorrectly mark authoritative DNS servers as not supporting EDNS, causing DNSSEC validation of records from those servers to fail.
Mitigation
Implement validation of EDNS responses to detect spoofed replies, or add mechanisms to verify authoritative server EDNS capabilities through multiple independent sources before marking servers as non-EDNS capable.
Weakness (CWE)
CWE-290
EPSS Score
0.34%
Probability of exploitation in next 30 days
27.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.