PowerDNS Recursor is vulnerable to denial of service attacks caused by null pointer dereferences due to missing consistency checks.
Claims
PowerDNS Recursor is vulnerable to denial of service attacks caused by null pointer dereferences due to missing consistency checks.
Parent: CybersecurityEntity: PowerDNSSub-entity: RecursorImpact: negativeDate: Apr 22, 2026Target: PowerDNS Recursor's security
PowerDNS internal web server is susceptible to denial of service attacks due to unlimited memory allocation from crafted web requests.
Parent: CybersecurityEntity: PowerDNSSub-entity: Internal Web ServerImpact: negativeDate: Apr 22, 2026Target: PowerDNS internal web server's security
PowerDNS RPZ data can lead to inconsistent data and crashes if there are concurrent transfers from a malfunctioning RPZ provider.
Parent: CybersecurityEntity: PowerDNSSub-entity: RPZ DataImpact: negativeDate: Apr 22, 2026Target: PowerDNS RPZ data handling
Source posts
๐จ EUVD-2026-24727
๐ Score: 5.9/10 (CVSS v3.1)
๐ฆ Product: Recursor, Recursor, Recursor
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24727
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24729
๐ Score: 5.9/10 (CVSS v3.1)
๐ฆ Product: Recursor, Recursor, Recursor
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24729
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24731
๐ Score: 4.4/10 (CVSS v3.1)
๐ฆ Product: Recursor, Recursor, Recursor
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24731
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24733
๐ Score: 4.4/10 (CVSS v3.1)
๐ฆ Product: Recursor, Recursor, Recursor
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24733
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24719
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: Recursor, Recursor, Recursor
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24719
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24720
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: dnsdist, Authoritative, Recursor (+4 more)
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24720
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24721
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: Recursor, Recursor, Recursor
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24721
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24723
๐ Score: 5.0/10 (CVSS v3.1)
๐ฆ Product: Recursor, Recursor, Recursor
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24723
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24725
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: Authoritative, Recursor, dnsdist (+4 more)
๐ข Vendor: PowerDNS
๐
Updated: 2026-04-22
๐ An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24725
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability