Executive brief
PowerDNS Authoritative Server is susceptible to a denial-of-service vulnerability within its GSS-TSIG implementation, a component used for secure DNS updates. An attacker could exploit concurrency and locking issues to cause the service to crash or become unresponsive. This would disrupt the organization's ability to resolve domain names, potentially taking websites and internal services offline.
Technical details
A vulnerability exists in the GSS-TSIG (Generic Security Service Algorithm for Secret Key Transaction Authentication for DNS) implementation of PowerDNS Authoritative Server. The flaw is rooted in improper concurrency management and locking defects. A remote, unauthenticated attacker can exploit these race conditions or locking issues over the network, though the attack complexity is rated as high, likely requiring specific timing or high-volume traffic to trigger the defect. Successful exploitation results in a denial of service (DoS) by impacting the availability of the DNS service. The vulnerability was reported by Open-Xchange and is tracked as CVE-2026-42002.
Affected products
- PowerDNS Authoritative Server
Timeline
- 2026-05-21: advisory: NVD published the CVE record based on Open-Xchange data.