Executive brief
A vulnerability in the PowerDNS Authoritative Server's internal web server could allow an authenticated user to crash the service. By sending a specially crafted web request, an attacker can cause the server to consume all available memory, leading to a denial of service. This component is disabled by default, which limits the risk to organizations that have manually enabled the internal web interface.
Technical details
A resource exhaustion vulnerability exists in the YaHTTP component of the PowerDNS Authoritative Server. An authenticated attacker with access to the internal web server can send a malicious HTTP request that triggers unlimited memory allocation in 'ext/yahttp/yahttp/reqresp.cpp'. This results in a denial of service (DoS) as the system runs out of memory. The vulnerability affects versions 4.9.x, 5.0.x, and 5.1.x. Users are advised to upgrade to versions 4.9.16, 5.0.6, or 5.1.2 respectively. The internal web server is disabled by default.
Affected products
- PowerDNS Authoritative Server 4.9.0 to 4.9.15, 5.0.0 to 5.0.5, 5.1.0 to 5.1.1
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory