CVE-2026-52688
published 2026-07-23CVE-2026-52688: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.18%
6.5th percentile
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| powerdns | recursor | >= 5.2.0 < 5.2.12 | 5.2.12 |
| powerdns | recursor | >= 5.3.0 < 5.3.9 | 5.3.9 |
| powerdns | recursor | >= 5.4.0 < 5.4.4 | 5.4.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
PowerDNS Recursor up to 5.2.11/5.3.8/5.4.3 input validation (Nessus ID 349324 / WID-SEC-2026-2471)
vuldb·2026-09-23·CVSS 7.5
CVE-2026-52688 [HIGH] PowerDNS Recursor up to 5.2.11/5.3.8/5.4.3 input validation (Nessus ID 349324 / WID-SEC-2026-2471)
A vulnerability labeled as critical has been found in PowerDNS Recursor up to 5.2.11/5.3.8/5.4.3. This impacts an unknown function. Such manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2026-52688. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
GHSA
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
ghsa_unreviewed·2026-07-23
CVE-2026-52688 [HIGH] CWE-295 RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-52688 pdns-recursor: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation [fedora-all]
bugzilla·2026-07-24·CVSS 7.5
CVE-2026-52688 [HIGH] CVE-2026-52688 pdns-recursor: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation [fedora-all]
CVE-2026-52688 pdns-recursor: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Bugzilla
CVE-2026-52688 pdns-recursor: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
bugzilla·2026-07-23·CVSS 7.5
CVE-2026-52688 [HIGH] CVE-2026-52688 pdns-recursor: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2026-52688 pdns-recursor: RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
2026-07-23
Published