Executive brief
A security issue has been identified in PowerDNS Authoritative Server involving how it handles zone transfers (AXFR). This vulnerability could allow an attacker to bypass certain name validation checks during the synchronization of DNS data between servers. If exploited, this could lead to the insertion of unauthorized or malformed DNS records, potentially impacting the integrity of DNS resolution for affected domains.
Technical details
PowerDNS Authoritative Server is vulnerable to an integrity-impacting flaw due to insufficient validation of names during Authoritative Transfer (AXFR) operations. An attacker capable of providing a zone transfer to a PowerDNS instance could potentially bypass name validation logic to inject records that should otherwise be rejected. The attack requires the attacker to be in a position to initiate or respond to an AXFR request, which typically requires specific network positioning or existing trust relationships (AC:H). Successful exploitation allows for unauthorized modification of DNS data (Integrity: High) but does not directly lead to data disclosure or service downtime. Users are advised to review their PowerDNS security advisories for specific version patches.
Affected products
- PowerDNS Authoritative Server
Timeline
- 2026-05-21: advisory: Initial disclosure of CVE-2026-42000