Executive brief
A vulnerability in PowerDNS Authoritative Server can cause the system to incorrectly handle DNS 'views' when receiving requests via the TCP PROXY protocol. This could allow an attacker to bypass intended network segmentation or access-control policies, potentially viewing DNS records they are not authorized to see. The issue primarily affects environments using load balancers or proxies that pass client information via the PROXY protocol.
Technical details
PowerDNS Authoritative Server is vulnerable to a logic error in how it processes 'views' (split-horizon DNS) when requests are received via the TCP PROXY protocol. The root cause is an incorrect mapping or validation of the source IP address provided in the PROXY header against the configured DNS views. An unauthenticated remote attacker can exploit this by sending specially crafted TCP PROXY requests to bypass source-based access controls or view-based restrictions. This could result in the disclosure of internal DNS records or the modification of expected query results. The vulnerability requires the PROXY protocol to be enabled and relies on a high-complexity attack vector involving specific network configurations.
Affected products
- PowerDNS Authoritative Server
Timeline
- 2026-05-21: disclosed: Initial advisory publication