Executive brief
A vulnerability in PowerDNS Recursor's Catalog Zones feature can cause the DNS service to crash. PowerDNS Recursor is a widely used tool that translates human-readable domain names into IP addresses for internet users. If exploited, this flaw could lead to a denial-of-service, preventing users from accessing websites and other online services.
Technical details
A denial-of-service vulnerability exists in PowerDNS Recursor due to incomplete validation of Start of Authority (SOA) records within Catalog Zones. The flaw is located in the rec-xfr.cc component. A remote attacker could potentially trigger a service crash by providing a specially crafted SOA record in a catalog zone. The attack requires a high degree of complexity (AC:H), likely involving the ability to influence or provide catalog zone data. Affected versions include the 5.2, 5.3, and 5.4 branches; users should update to versions 5.2.11, 5.3.8, or 5.4.3 respectively.
Affected products
- PowerDNS Recursor 5.2.0 to 5.2.10, 5.3.0 to 5.3.7, 5.4.0 to 5.4.2
Timeline
- 2026-06-25: disclosed: CVE published by Open-Xchange
- 2026-06-25: advisory: PowerDNS security advisory 2026-08 released