Junglewise Threat Intelligence

CVE-2026-42396: PowerDNS Authoritative Server denial of service in catalog zone transfer

CVE-2026-42396 · Severity: medium · CVSS 4.9 · Published 2026-05-21

Technologies: Powerdns Authoritative Server. Vendors: Powerdns.

Executive brief

A vulnerability in PowerDNS Authoritative Server can cause failures in the synchronization of DNS zone data. This occurs when the system fails to properly validate specific member zone data during a catalog zone transfer. If exploited, this could lead to a denial of service for DNS management operations, preventing secondary servers from receiving updated records and potentially impacting the availability of domain name resolution.

Technical details

PowerDNS Authoritative Server is vulnerable to a denial of service condition during catalog zone transfers. The root cause is insufficient validation of member zone data within the catalog zone. An attacker with high privileges (sufficient to modify or inject data into a catalog zone) can provide malformed or unexpected member zone data that causes the transfer process to fail. This prevents the synchronization of DNS zones across the infrastructure. The vulnerability is tracked as CVE-2026-42396 and was reported by Open-Xchange.

Affected products

  • PowerDNS Authoritative Server

Timeline

  • 2026-05-21: disclosed: Initial advisory publication

References

Related threats