Executive brief
PowerDNS Recursor, a service used to resolve internet domain names for users, contains a vulnerability in how it validates data from other servers. An attacker could potentially provide incorrect information to the system, leading to data integrity issues. This update introduces stricter validation to ensure the accuracy of the information the service provides to its users.
Technical details
PowerDNS Recursor versions 5.4.0 through 5.4.2 are affected by a lack of rigorous validation for incoming DNS responses from authoritative servers. This vulnerability allows a remote, unauthenticated attacker to potentially inject or manipulate DNS data by sending crafted responses that bypass existing checks. The root cause is insufficient validation logic within the 5.4.x branch, specifically addressed in the pdns_recursor.cc component. An exploit could lead to unauthorized modification of DNS cache data. Users are advised to upgrade to version 5.4.3 or later to receive the hardening fix.
Affected products
- PowerDNS Recursor 5.4.0 to 5.4.2
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory