Junglewise Threat Intelligence

CVE-2026-33612: PowerDNS Recursor cache poisoning in ZoneToCache function

CVE-2026-33612 · Severity: high · CVSS 7.5 · Published 2026-06-25

Technologies: Powerdns Recursor. Vendors: Powerdns.

Executive brief

PowerDNS Recursor, a tool used by internet service providers to look up website addresses for users, is vulnerable to a cache poisoning attack. A malicious server can send specially crafted data that tricks the recursor into storing incorrect information in its memory. This could allow an attacker to redirect users to fraudulent websites or disrupt internet services.

Technical details

A cache poisoning vulnerability exists in the PowerDNS Recursor's 'Zone to cache' module (specifically within rec-zonetocache.cc). An attacker controlling a malicious authoritative DNS server can provide a crafted zone file during a ZoneToCache operation. This allows the attacker to inject unauthorized DNS records into the recursor's cache, potentially redirecting traffic for arbitrary domains. The attack requires the ZoneToCache feature to be active and the recursor to interact with the malicious server. Patches are available in versions 5.2.11, 5.3.8, and 5.4.3.

Affected products

  • PowerDNS Recursor 5.2.0 to 5.2.10, 5.3.0 to 5.3.7, 5.4.0 to 5.4.2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats