VYPR

Recursor

by PowerDNS

CVEs (56)

  • CVE-2017-15094MedJan 23, 2018
    risk 0.39cvss 5.9epss 0.03

    An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are only parsed when validation is enabled by setting dnssec to a value other than…

  • CVE-2026-33262MedApr 22, 2026
    risk 0.38cvss 5.9epss 0.00

    An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.

  • CVE-2026-33261MedApr 22, 2026
    risk 0.38cvss 5.9epss 0.00

    A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.

  • CVE-2017-15090MedJan 23, 2018
    risk 0.38cvss 5.9epss 0.01

    An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in…

  • CVE-2020-14196MedJul 1, 2020
    risk 0.35cvss 5.3epss 0.02

    In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.

  • CVE-2018-14626MedNov 29, 2018
    risk 0.35cvss 5.3epss 0.03

    PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollution via crafted query that can lead to denial of service.

  • CVE-2018-10851MedNov 29, 2018
    risk 0.35cvss 5.3epss 0.06

    PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.

  • CVE-2018-14644MedNov 9, 2018
    risk 0.35cvss 5.3epss 0.05

    An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DNSSEC validation. It only arises if the parent zone is signed, and all the…

  • CVE-2017-15093MedJan 23, 2018
    risk 0.35cvss 5.3epss 0.01

    When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to…

  • CVE-2026-33260MedApr 22, 2026
    risk 0.34cvss 5.3epss 0.01

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

  • CVE-2026-33258MedApr 22, 2026
    risk 0.34cvss 5.3epss 0.01

    By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.

  • CVE-2026-33257MedApr 22, 2026
    risk 0.34cvss 5.3epss 0.01

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

  • CVE-2026-33256MedApr 22, 2026
    risk 0.34cvss 5.3epss 0.01

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

  • CVE-2026-24027MedFeb 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Crafted zones can lead to increased incoming network traffic.

  • CVE-2026-0398MedFeb 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

  • CVE-2025-59029MedDec 9, 2025
    risk 0.34cvss 5.3epss 0.00

    An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

  • CVE-2026-33259MedApr 22, 2026
    risk 0.33cvss 5.0epss 0.00

    Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.

  • CVE-2026-33601MedApr 22, 2026
    risk 0.29cvss 4.4epss 0.01

    If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

  • CVE-2026-33600MedApr 22, 2026
    risk 0.29cvss 4.4epss 0.01

    An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

  • CVE-2016-7074MedSep 11, 2018
    risk 0.28cvss 5.3epss 0.01

    An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in position of man-in-the-middle to alter the content of an AXFR because of insufficient validation of TSIG signatures. A missing check that the TSIG record is…