Powerdns Recursor vulnerabilities
63 known vulnerabilities affecting powerdns/recursor.
Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH29MEDIUM29LOW3
Vulnerabilities
Page 4 of 4
CVE-2026-52684P4LOWCVSS 3.7≥ 0.0.0, < 5.5.02026-07-23
CVE-2026-52684 [LOW] CVE-2026-52684: If the auth responds very slowly and the records expire in between, the capping of TTLs is not enfor
If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the
child records are used immediately if not expired and thus valid, or the
records are expired, and in that case not used. So this case
can only happen if almost expired records are use
nvd
CVE-2026-52686P4LOWCVSS 3.7≥ 5.2.0, < 5.2.12≥ 5.3.0, < 5.3.9+1 more2026-07-23
CVE-2026-52686 [LOW] CWE-347 CVE-2026-52686: The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are acc
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
nvd
CVE-2018-1000003P4LOWCVSS 3.7v4.1.02018-01-22
CVE-2018-1000003 [LOW] CWE-20 CVE-2018-1000003: Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attac
Improper input validation bugs in DNSSEC validators components in PowerDNS version 4.1.0 allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.
nvd
← Previous4 / 4