โ† All reports

PowerDNS Recursor is vulnerable to denial of service attacks caused by null pointer dereferences due to missing consistency checks.

CybersecurityTechnologyConflictDenial Of ServiceApr 22, 2026score 0.179 posts ยท 0 replies across 1 instances
This thread discusses multiple vulnerabilities in PowerDNS products, including denial of service attacks through null pointer dereferences, memory allocation issues, and inconsistencies in RPZ data. These vulnerabilities highlight security risks in DNS-related software.

Claims

PowerDNS Recursor is vulnerable to denial of service attacks caused by null pointer dereferences due to missing consistency checks.
Parent: CybersecurityEntity: PowerDNSSub-entity: RecursorImpact: negativeDate: Apr 22, 2026Target: PowerDNS Recursor's security
PowerDNS internal web server is susceptible to denial of service attacks due to unlimited memory allocation from crafted web requests.
Parent: CybersecurityEntity: PowerDNSSub-entity: Internal Web ServerImpact: negativeDate: Apr 22, 2026Target: PowerDNS internal web server's security
PowerDNS RPZ data can lead to inconsistent data and crashes if there are concurrent transfers from a malfunctioning RPZ provider.
Parent: CybersecurityEntity: PowerDNSSub-entity: RPZ DataImpact: negativeDate: Apr 22, 2026Target: PowerDNS RPZ data handling

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24727 ๐Ÿ“Š Score: 5.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Recursor, Recursor, Recursor ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24727 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24729 ๐Ÿ“Š Score: 5.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Recursor, Recursor, Recursor ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24729 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24731 ๐Ÿ“Š Score: 4.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Recursor, Recursor, Recursor ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24731 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24733 ๐Ÿ“Š Score: 4.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Recursor, Recursor, Recursor ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24733 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24719 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Recursor, Recursor, Recursor ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24719 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24720 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: dnsdist, Authoritative, Recursor (+4 more) ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24720 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24721 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Recursor, Recursor, Recursor ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24721 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24723 ๐Ÿ“Š Score: 5.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Recursor, Recursor, Recursor ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24723 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24725 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Authoritative, Recursor, dnsdist (+4 more) ๐Ÿข Vendor: PowerDNS ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24725 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability