vciy

CVEs we hold for Powerdns

Records whose assigning authority named Powerdns as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-52690Spoofed answers can mark an authoritative non-EDNS capablePowerDNS Recursor
CVE-2026-52688RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationPowerDNS Recursor
CVE-2026-52686Wildcard CNAME proof validation bypassPowerDNS Recursor
CVE-2026-52684Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning AttackPowerDNS Recursor
CVE-2026-42396Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to FailPowerDNS Authoritative
CVE-2026-42390ZONEMD validation can be bypassedPowerDNS Recursor
CVE-2026-42389Reject more queries with invalid header valuesPowerDNS Recursor
CVE-2026-42388Missing input validation for catalog zonesPowerDNS Recursor
CVE-2026-42387Insufficient input validation in ZoneToCachePowerDNS Recursor
CVE-2026-42005Insufficient input validation of internal web serverPowerDNS Authoritative
CVE-2026-42004EDNS options smugglingPowerDNS DNSdist
CVE-2026-42002Concurrency and locking defects in GSS-TSIGPowerDNS Authoritative
CVE-2026-42001Insufficient Validation of Autoprimary SOA QueriesPowerDNS Authoritative
CVE-2026-42000Insufficient Validation of Names During AXFRPowerDNS Authoritative
CVE-2026-41999Incorrect Behaviour of Views with TCP PROXY RequestsPowerDNS Authoritative
CVE-2026-40211Denial of service via crafted DoH3 queriesPowerDNS DNSdist
CVE-2026-40210Out-of-bounds read in SetMacAddrActionPowerDNS DNSdist
CVE-2026-40209Denial of service via IXFR queriesPowerDNS DNSdist
CVE-2026-40208Denial of service via DoH3 queriesPowerDNS DNSdist
CVE-2026-40012Information about ECS zero scoped answers might leak to clients that use a specific ECSPowerDNS Recursor
CVE-2026-40011Prometheus denial of service via crafted DNS queriesPowerDNS DNSdist
CVE-2026-33612ZoneToCache can poison the cachePowerDNS Recursor
CVE-2026-33611Insufficient validation of HTTPS and SVCB recordsPowerDNS Authoritative
CVE-2026-33610Possible file descriptor exhaustion in forward-dnsupdatePowerDNS Authoritative
CVE-2026-33609LDAP DN injectionPowerDNS Authoritative
CVE-2026-33608Incomplete domain name sanitization duringPowerDNS Authoritative
CVE-2026-33602Off-by-one access when processing crafted UDP responsesPowerDNS DNSdist
CVE-2026-33601Insufficient validation of zonemd recordPowerDNS Recursor
CVE-2026-33600Null pointer dereference in RPZ transferPowerDNS Recursor
CVE-2026-33599Out-of-bounds read in service discoveryPowerDNS DNSdist
CVE-2026-33598Out-of-bounds read in cache inspection via LuaPowerDNS DNSdist
CVE-2026-33597PRSD detection denial of servicePowerDNS DNSdist
CVE-2026-33596TCP backend stream ID overflowPowerDNS DNSdist
CVE-2026-33595DoQ/DoH3 excessive memory allocationPowerDNS DNSdist
CVE-2026-33594Outgoing DoH excessive memory allocationPowerDNS DNSdist
CVE-2026-33593Denial of service via crafted DNSCrypt queryPowerDNS DNSdist
CVE-2026-33262Insufficient validation of cookie replyPowerDNS Recursor
CVE-2026-33261Null pointer accces in aggressive NSEC(3) cachePowerDNS Recursor
CVE-2026-33260Insufficient input validation of internal webserverPowerDNS Recursor
CVE-2026-33259Concurrent modification of RPZ data can lead to denial of servcePowerDNS Recursor
CVE-2026-33258Crafted zones can cause increased resource usagePowerDNS Recursor
CVE-2026-33257Insufficient input validation of internal webserverPowerDNS Recursor
CVE-2026-33256Unbounded memory allocation by internal web serverPowerDNS Recursor
CVE-2026-33254Resource exhaustion via DoQ/DoH3 connectionsPowerDNS DNSdist
CVE-2026-27854Use after free when parsing EDNS options in LuaPowerDNS DNSdist
CVE-2026-27853Out-of-bounds write when rewriting large DNS packetsPowerDNS DNSdist
CVE-2026-24030Unbounded memory allocation for DoQ and DoH3PowerDNS DNSdist
CVE-2026-24029DNS over HTTPS ACL bypassPowerDNS DNSdist
CVE-2026-24028Out-of-bounds read when parsing DNS packets via LuaPowerDNS DNSdist
CVE-2026-24027Crafted zones can lead to increased incoming network trafficPowerDNS Recursor
CVE-2026-0398Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in RecursorPowerDNS Recursor
CVE-2026-0397Information disclosure via CORS misconfigurationPowerDNS DNSdist
CVE-2026-0396HTML injection in the web dashboardPowerDNS DNSdist
CVE-2025-59030Insufficient validation of incoming notifies over TCP can lead to a denial of service in RecursorPowerDNS Recursor
CVE-2025-59029Internal logic flaw in cache management can lead to a denial of service in PowerDNS RecursorPowerDNS Recursor
CVE-2025-59024Crafted delegations or IP fragments can poison cached delegations in RecursorPowerDNS Recursor
CVE-2025-59023Crafted delegations or IP fragments can poison cached delegations in RecursorPowerDNS Recursor
CVE-2025-30195A crafted zone can lead to an illegal memory access in the PowerDNS RecursorPowerDNS Recursor
CVE-2025-30194Denial of service via crafted DoH exchangePowerDNS DNSdist
CVE-2025-30193Denial of service via crafted TCP exchangePowerDNS DNSdist
CVE-2025-30192A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attemptsPowerDNS Recursor
CVE-2025-30187Denial of service via crafted DoH exchange in PowerDNS DNSdistPowerDNS DNSdist
CVE-2024-25590Crafted responses can lead to a denial of service due to cache inefficiencies in the RecursorPowerDNS Recursor
CVE-2024-25583Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configuredPowerDNS Recursor
CVE-2024-25581Transfer requests received over DoH can lead to a denial of service in DNSdistPowerDNS DNSdist
CVE-2023-26437Deterred spoofing attempts can lead to authoritative servers being marked unavailablePowerDNS Recursor
CVE-2019-10163no title heldPowerDNS pdns
CVE-2019-10162no title heldPowerDNS pdns
CVE-2017-15120no title heldPowerDNS pdns-recursor
CVE-2017-15094no title heldPowerDNS Recursor
CVE-2017-15093no title heldPowerDNS Recursor
CVE-2017-15092no title heldPowerDNS Recursor
CVE-2017-15091no title heldPowerDNS Authoritative
CVE-2017-15090no title heldPowerDNS
CVE-2015-5230no title heldPowerDNS Authoritative Server

75 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.