Executive brief
A vulnerability has been identified in PowerDNS Authoritative Server, a widely used system for managing internet domain names. An attacker can exploit this flaw to disrupt the availability of the DNS service, potentially causing websites and email services to become unreachable. This issue specifically affects how the server handles automated updates from primary servers, leading to a denial-of-service condition.
Technical details
PowerDNS Authoritative Server fails to properly validate Start of Authority (SOA) queries when configured with 'autoprimary' (formerly 'superslave') functionality. An unauthenticated remote attacker can send specially crafted SOA queries to the server, which may lead to resource exhaustion or service instability. This vulnerability is classified as a Denial of Service (DoS) because it impacts the availability of the DNS daemon without directly compromising data confidentiality or integrity. Users are advised to review their PowerDNS security advisories for specific version patches and configuration mitigations.
Affected products
- PowerDNS Authoritative Server
Timeline
- 2026-05-21: advisory: NVD publication date