Junglewise Threat Intelligence

CVE-2026-42388: PowerDNS Recursor denial of service in Catalog Zones

CVE-2026-42388 · Severity: medium · CVSS 5.9 · Published 2026-06-25

Technologies: Powerdns Recursor. Vendors: Powerdns.

Executive brief

A vulnerability in PowerDNS Recursor's Catalog Zones feature can cause the DNS service to crash. PowerDNS Recursor is a widely used tool that translates human-readable domain names into IP addresses for internet users. If exploited, this flaw could lead to a denial-of-service, preventing users from accessing websites and other online services.

Technical details

A denial-of-service vulnerability exists in PowerDNS Recursor due to incomplete validation of Start of Authority (SOA) records within Catalog Zones. The flaw is located in the rec-xfr.cc component. A remote attacker could potentially trigger a service crash by providing a specially crafted SOA record in a catalog zone. The attack requires a high degree of complexity (AC:H), likely involving the ability to influence or provide catalog zone data. Affected versions include the 5.2, 5.3, and 5.4 branches; users should update to versions 5.2.11, 5.3.8, or 5.4.3 respectively.

Affected products

  • PowerDNS Recursor 5.2.0 to 5.2.10, 5.3.0 to 5.3.7, 5.4.0 to 5.4.2

Timeline

  • 2026-06-25: disclosed: CVE published by Open-Xchange
  • 2026-06-25: advisory: PowerDNS security advisory 2026-08 released

References

Related threats