Debian Pdns-Recursor vulnerabilities
48 known vulnerabilities affecting debian/pdns-recursor.
Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM19LOW9
Vulnerabilities
Page 2 of 3
CVE-2019-3806P3HIGHCVSS 8.1fixed in pdns-recursor 4.1.9-1 (bookworm)2019
CVE-2019-3806 [HIGH] CVE-2019-3806: pdns-recursor - An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 w...
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.
Scope: local
bookworm: resolved (fixed in 4.1.9-1)
bullseye: resolved (fixed in 4.1.9-1)
forky: resolved (fixed in 4
debian
CVE-2020-10995P3HIGHCVSS 7.5fixed in pdns-recursor 4.3.1-1 (bookworm)2020
CVE-2020-10995 [HIGH] CVE-2020-10995: pdns-recursor - PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently def...
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party authoritative name servers. The attack uses a crafted reply by an authoritative name server to amplify the resulting traff
debian
CVE-2025-30192P3HIGHCVSS 7.5fixed in pdns-recursor 5.2.4-2 (forky)2025
CVE-2025-30192 [HIGH] CVE-2025-30192: pdns-recursor - An attacker spoofing answers to ECS enabled requests sent out by the Recursor ha...
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS enabled requests and enforcing stricter validation of the received answers. The most strict mitigation done wh
debian
CVE-2024-25583P3HIGHCVSS 7.5fixed in pdns-recursor 4.8.8-1 (bookworm)2024
CVE-2024-25583 [HIGH] CVE-2024-25583: pdns-recursor - A crafted response from an upstream server the recursor has been configured to f...
A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.
Scope: local
bookworm: resolved (fixed in 4.8.8-1)
bullseye: resolved
forky: resolved (fixed in 4.9.5-1)
sid: resolved (
debian
CVE-2025-30195P3LOWCVSS 7.5fixed in pdns-recursor 5.2.1-1 (forky)2025
CVE-2025-30195 [HIGH] CVE-2025-30195: pdns-recursor - An attacker can publish a zone containing specific Resource Record Sets. Process...
An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patched 5.2.1 version. We would like to thank Volodymyr Ilyin for bringing this issue to our attention.
Scope: local
b
debian
CVE-2018-10851P3MEDIUMCVSS 5.3fixed in pdns 4.1.5-1 (bookworm)2018
CVE-2018-10851 [MEDIUM] CVE-2018-10851: pdns - PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and P...
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.
Scope: local
bookworm: resolved (fixed in 4.1.5-1)
bullseye: resolved (fixed in 4.1.5-1)
forky: resolved (fixed in 4.1.5-1
debian
CVE-2024-25590P3HIGHCVSS 7.5fixed in pdns-recursor 4.8.8-1+deb12u1 (bookworm)2024
CVE-2024-25590 [HIGH] CVE-2024-25590: pdns-recursor - An attacker can publish a zone containing specific Resource Record Sets. Repea...
An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.
Scope: local
bookworm: resolved (fixed in 4.8.8-1+deb12u1)
bullseye: open
forky: resolved (fixed in 5.0.9-1)
sid: resolved (fixed in 5.0.9-1)
trixie: resolved (fixed in 5.0.9-1)
debian
CVE-2025-59024P3MEDIUMCVSS 6.5fixed in pdns-recursor 5.3.1-1 (forky)2025
CVE-2025-59024 [MEDIUM] CVE-2025-59024: pdns-recursor - Crafted delegations or IP fragments can poison cached delegations in Recursor.
Crafted delegations or IP fragments can poison cached delegations in Recursor.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.3.1-1)
sid: resolved (fixed in 5.3.1-1)
trixie: resolved (fixed in 5.2.6-0+deb13u1)
debian
CVE-2018-14626P3MEDIUMCVSS 5.3fixed in pdns 4.1.5-1 (bookworm)2018
CVE-2018-14626 [MEDIUM] CVE-2018-14626: pdns - PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor ...
PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can lead to denial of service.
Scope: local
bookworm: resolved (fixed in 4.1.5-1)
bullseye: resolved (fixed in 4.1.5-1)
forky: resolved (fixed in 4.1.5-1)
sid: resolved (fixed in 4.1.5-1)
trixie:
debian
CVE-2018-14644P4MEDIUMCVSS 5.3fixed in pdns-recursor 4.1.7-1 (bookworm)2018
CVE-2018-14644 [MEDIUM] CVE-2018-14644: pdns-recursor - An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1....
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the authoritative servers for that parent zone answer with FORMERR to a query for at least
debian
CVE-2022-37428P4MEDIUMCVSS 6.5fixed in pdns-recursor 4.7.2-1 (bookworm)2022
CVE-2022-37428 [MEDIUM] CVE-2022-37428: pdns-recursor - PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logg...
PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.
Scope: local
bookworm: resolved (fixed in 4.7.2-1)
bullseye: open
forky: resolved (fixed in 4.7.2-1)
sid:
debian
CVE-2017-15094P4MEDIUMCVSS 5.9fixed in pdns-recursor 4.0.7-1 (bookworm)2017
CVE-2017-15094 [MEDIUM] CVE-2017-15094: pdns-recursor - An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0...
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is enabled by setting dnssec to a value other than off or process-no-validate (default).
Scope: local
bookworm: resolved (fixed in 4.
debian
CVE-2017-15090P4MEDIUMCVSS 5.9fixed in pdns-recursor 4.0.7-1 (bookworm)2017
CVE-2017-15090 [MEDIUM] CVE-2017-15090: pdns-recursor - An issue has been found in the DNSSEC validation component of PowerDNS Recursor ...
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid
debian
CVE-2016-7073P4MEDIUMCVSS 5.3fixed in pdns 4.0.2-1 (bookworm)2016
CVE-2016-7073 [MEDIUM] CVE-2016-7073: pdns - An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recurs...
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check of the TSIG time and fudge values was found in AXFRRetriever, leading to a possible replay attack.
Scope: local
bookw
debian
CVE-2020-14196P4LOWCVSS 5.3fixed in pdns-recursor 4.3.2-1 (bookworm)2020
CVE-2020-14196 [MEDIUM] CVE-2020-14196: pdns-recursor - In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the A...
In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.
Scope: local
bookworm: resolved (fixed in 4.3.2-1)
bullseye: resolved (fixed in 4.3.2-1)
forky: resolved (fixed in 4.3.2-1)
sid: resolved (fixed in 4.3.2-1)
trixie: resolved (fixed in 4.3.2-1)
debian
CVE-2017-15093P4MEDIUMCVSS 5.3fixed in pdns-recursor 4.0.7-1 (bookworm)2017
CVE-2017-15093 [MEDIUM] CVE-2017-15093: pdns-recursor - When api-config-dir is set to a non-empty value, which is not the case by defaul...
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwa
debian
CVE-2026-24027P4MEDIUMCVSS 5.3fixed in pdns-recursor 5.3.5-1 (forky)2026
CVE-2026-24027 [MEDIUM] CVE-2026-24027: pdns-recursor - Crafted zones can lead to increased incoming network traffic.
Crafted zones can lead to increased incoming network traffic.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 5.3.5-1)
sid: resolved (fixed in 5.3.5-1)
trixie: resolved (fixed in 5.2.8-0+deb13u1)
debian
CVE-2008-1637P4MEDIUMCVSS 6.8fixed in pdns-recursor 3.1.7-1 (bookworm)2008
CVE-2008-1637 [MEDIUM] CVE-2008-1637: pdns-recursor - PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRX...
PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole see
debian
CVE-2016-7074P4MEDIUMCVSS 5.3fixed in pdns 4.0.2-1 (bookworm)2016
CVE-2016-7074 [MEDIUM] CVE-2016-7074: pdns - An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recurs...
An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check that the TSIG record is the last one, leading to the possibility of parsing records that are not covered by the TSIG
debian
CVE-2025-59029P4LOWCVSS 5.3fixed in pdns-recursor 5.3.3-1 (forky)2025
CVE-2025-59029 [MEDIUM] CVE-2025-59029: pdns-recursor - An attacker can trigger an assertion failure by requesting crafted DNS records, ...
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 5.3.3-1)
sid: resolved (fixed in 5.3.3-1)
trixie: resolved
debian