Junglewise Threat Intelligence

CVE-2026-42387: PowerDNS Recursor denial of service in ZoneToCache

CVE-2026-42387 · Severity: medium · CVSS 5.9 · Published 2026-06-25

Technologies: Powerdns Recursor. Vendors: Powerdns.

Executive brief

A vulnerability in the PowerDNS Recursor, a service used to translate human-readable domain names into IP addresses, could allow a malicious server to crash the system. By sending a specially crafted data zone, an attacker can trigger a service failure, leading to a denial of service for users relying on that DNS server. This impact is limited to service availability and does not involve data theft or unauthorized access.

Technical details

A denial of service vulnerability exists in PowerDNS Recursor's ZoneToCache function due to insufficient input validation in the zonemd.cc component. A malicious authoritative server can exploit this by sending a specially crafted zone, causing the Recursor process to crash. The attack requires the Recursor to be configured to fetch and cache zones from the attacker-controlled server. The vulnerability is addressed in versions 5.2.11, 5.3.8, and 5.4.3.

Affected products

  • PowerDNS Recursor 5.2.0 to 5.2.10, 5.3.0 to 5.3.7, 5.4.0 to 5.4.2

Timeline

  • 2026-06-25: disclosed: Initial advisory publication

References

Related threats