VYPR

PowerDNS Authoritative Server

by PowerDNS

Source repositories

CVEs (29)

  • CVE-2026-33257MedApr 22, 2026
    risk 0.34cvss 5.3epss 0.01

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

  • CVE-2026-42396MedMay 21, 2026
    risk 0.32cvss 4.9epss 0.00

    Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

  • CVE-2026-41999MedMay 21, 2026
    risk 0.31cvss 4.8epss 0.00

    Incorrect Behaviour of Views with TCP PROXY Requests

  • CVE-2026-33610MedApr 22, 2026
    risk 0.31cvss 5.9epss 0.00

    A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS update request to it.

  • CVE-2020-17482MedOct 2, 2020
    risk 0.28cvss 4.3epss 0.03

    An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.

  • CVE-2019-10163MedJul 30, 2019
    risk 0.28cvss 4.3epss 0.01

    A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only…

  • CVE-2016-7072MedSep 10, 2018
    risk 0.28cvss 5.3epss 0.06

    An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated attacker to cause a denial of service by opening a large number of TCP connections to the web server. If the web server runs out of file descriptors, it triggers…

  • CVE-2026-33609MedApr 22, 2026
    risk 0.27cvss 5.3epss 0.00

    Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.

  • CVE-2008-3337Aug 8, 2008
    risk 0.00cvss epss 0.06

    PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217.

Page 2 of 2