CVE-2026-52686
published 2026-07-23CVE-2026-52686: The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer…
PriorityP414low3.7CVSS 3.1
AVNACHPRNUINSUCNILAN
EPSS
0.11%
1.4th percentile
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| powerdns | recursor | >= 5.2.0 < 5.2.12 | 5.2.12 |
| powerdns | recursor | >= 5.3.0 < 5.3.9 | 5.3.9 |
| powerdns | recursor | >= 5.4.0 < 5.4.4 | 5.4.4 |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs
vendor_redhat·2026-07-23·CVSS 3.7
CVE-2026-52686 [LOW] CWE-347 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs
pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
A flaw was found in pdns-recursor. This vulnerability allows a remote attacker to bypass DNSSEC (Domain Name System Security Extensions) validation. The flaw occurs because the system accepts wildcard expansion proofs (NSEC/NSEC3 records) without proper signature validation when the wildcard answer is a CNAME (Canonical Name) or DNAME (Delegation Name) record. This can lead to an attacker providing forged DNS responses, potentially resulting in information integrity issues.
Statement: Red Hat Product Securi
GHSA
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
ghsa_unreviewed·2026-07-23
CVE-2026-52686 [LOW] CWE-347 The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs [fedora-all]
bugzilla·2026-07-24·CVSS 3.7
CVE-2026-52686 [LOW] CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs [fedora-all]
CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
Bugzilla
CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs [epel-all]
bugzilla·2026-07-24·CVSS 3.7
CVE-2026-52686 [LOW] CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs [epel-all]
CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
Bugzilla
CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs
bugzilla·2026-07-23·CVSS 3.7
CVE-2026-52686 [LOW] CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs
CVE-2026-52686 pdns-recursor: pdns-recursor: DNSSEC validation bypass due to unsigned wildcard expansion proofs
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
2026-07-23
Published