Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Recursor HIGH 8.2
CVE-2025-59023

Crafted delegations or IP fragments can poison cached delegations in Recursor.

Fix: 5.1.8 / 5.2.6+
Fix from $1,950 2026-02-09
Recursor MEDIUM 6.5
CVE-2025-59024

Crafted delegations or IP fragments can poison cached delegations in Recursor.

Fix: 5.1.8 / 5.2.6+
Fix from $1,600 2026-02-09
Recursor HIGH 7.5
CVE-2025-59030

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

Fix: 5.1.9 / 5.2.7+
Fix from $1,950 2025-12-09
Recursor MEDIUM 5.3
CVE-2025-59029

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a q…

Mitigation only
Fix from $1,600 2025-12-09
Recursor MEDIUM 5.3
CVE-2023-26437

Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5…

Fix: 4.6.6 / 4.7.5+
Fix from $1,600 2023-04-04
Recursor HIGH 7.5
CVE-2023-22617EPSS 7%

A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured …

Mitigation only
Fix from $1,950 2023-01-21
Authoritative Server HIGH 7.5
CVE-2021-36754EPSS 65%

PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-…

Fix: 4.5.1+
Fix from $1,950 2021-07-30
Recursor HIGH 7.5
CVE-2020-25829EPSS 7%

An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can cause the cached record…

Fix: 4.1.18 / 4.2.5+
Fix from $1,950 2020-10-16
Authoritative CRITICAL 9.8
CVE-2020-24698

An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might…

Fix: after 4.3.0
Fix from $2,300 2020-10-02
Authoritative HIGH 8.1
CVE-2020-24696

An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can t…

Fix: after 4.3.0
Fix from $1,950 2020-10-02
Authoritative HIGH 7.5
CVE-2020-24697

An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can c…

Fix: after 4.3.0
Fix from $1,950 2020-10-02
Recursor MEDIUM 5.3
CVE-2020-14196

In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enfo…

Fix: after 4.3.1
Fix from $1,600 2020-07-01
Recursor HIGH 8.8
CVE-2020-10030EPSS 24%

An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's ho…

Fix: after 4.3.0
Fix from $1,950 2020-05-19
Authoritative HIGH 7.5
CVE-2019-10162

A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit…

Fix: 4.0.8 / 4.1.10+
Fix from $1,950 2019-07-30
Recursor CRITICAL 9.8
CVE-2019-3807

An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative…

Fix: after 4.1.8
Fix from $2,300 2019-01-29
Recursor HIGH 8.1
CVE-2019-3806

An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP …

Fix: 4.1.9+
Fix from $1,950 2019-01-29
Recursor HIGH 7.5
CVE-2018-16855EPSS 59%

An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory rea…

Fix: 4.1.8+
Fix from $1,950 2018-12-03
Authoritative HIGH 7.5
CVE-2018-10851EPSS 6%

PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulne…

Fix: after 4.1.4
Fix from $1,950 2018-11-29
Authoritative HIGH 7.5
CVE-2018-14626

PowerDNS Authoritative Server 4.1.0 up to 4.1.4 inclusive and PowerDNS Recursor 4.0.0 up to 4.1.4 inclusive are vulnerable to a packet cache pollutio…

Fix: after 4.1.4
Fix from $1,950 2018-11-29
Dnsdist MEDIUM 5.9
CVE-2018-14663

An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such that the addition of…

Fix: after 1.3.2
Fix from $1,600 2018-11-26
Recursor MEDIUM 5.9
CVE-2018-14644

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can…

Fix: after 4.1.4
Fix from $1,600 2018-11-09
Dnsdist HIGH 7.5
CVE-2016-7069

An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is confi…

Fix: after 1.2.0
Fix from $1,950 2018-09-11
Pdns HIGH 7.8
CVE-2018-1046

pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay. In the dnsreplay tool provided with PowerDNS Authoritative, replaying a sp…

Fix: 4.1.2+
Fix from $1,950 2018-07-16
Authoritative HIGH 7.1
CVE-2017-15091

An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some o…

Fix: after 4.0.4
Fix from $1,950 2018-01-23
Recursor MEDIUM 6.1
CVE-2017-15092

A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS qu…

Fix: after 4.0.6
Fix from $1,600 2018-01-23
Recursor MEDIUM 5.9
CVE-2017-15090

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might …

Fix: after 4.0.6
Fix from $1,600 2018-01-23
Recursor MEDIUM 5.9
CVE-2017-15094

An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing sp…

Fix: after 4.0.6
Fix from $1,600 2018-01-23
Recursor MEDIUM 5.3
CVE-2017-15093

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x…

Fix: after 4.0.6
Fix from $1,600 2018-01-23
Dnsdist HIGH 8.8
CVE-2017-7557

dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.

Patch available
Fix from $1,950 2017-08-22
Authoritative HIGH 7.5
CVE-2016-5427EPSS 63%

PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a den…

Fix: after 3.4.9
Fix from $1,950 2016-09-21