MEDIUM

CVE-2026-52690

2026-06-25 CVSS v3.1
CVSS
5.9

Description

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

Summary dbcve.org

A spoofing vulnerability in DNS Recursor allows attackers to send伪造 replies that incorrectly mark authoritative DNS servers as not supporting EDNS, causing DNSSEC validation of records from those servers to fail.

Mitigation

Implement validation of EDNS responses to detect spoofed replies, or add mechanisms to verify authoritative server EDNS capabilities through multiple independent sources before marking servers as non-EDNS capable.

Weakness (CWE)

CWE-290

EPSS Score

0.34%
Probability of exploitation in next 30 days
27.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE