VendorsPowerDNSrecursorany version
Vulnerabilities

PowerDNS Recursor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

46CVEs
CVE-2026-0398
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor
Published 2026-02-09 · Analyzed
5.3EPSS 0.003
CVE-2014-8601
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it.
Published 2014-12-10 · Modified
5.0EPSS 0.689
CVE-2006-4252
PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.
Published 2006-11-14 · Modified
5.0EPSS 0.060
CVE-2026-33259
Concurrent modification of RPZ data can lead to denial of servce
Published 2026-04-22 · Analyzed
5.0EPSS 0.003
CVE-2026-33600
Null pointer dereference in RPZ transfer
Published 2026-04-22 · Analyzed
4.9EPSS 0.007
CVE-2026-33601
Insufficient validation of zonemd record
Published 2026-04-22 · Analyzed
4.9EPSS 0.007
← Prev2 / 2