Executive brief
Technitium DNS Server is a tool used to manage network traffic and domain name resolution. A vulnerability in how it handles security records allows an attacker to force the server into a loop of aggressive network requests. This can lead to excessive network traffic, potentially slowing down the server or causing a denial-of-service condition for legitimate users.
Technical details
Technitium DNS Server is vulnerable to asymmetric resource consumption (amplification) due to insufficient control of network message volume. The server's DNSSEC validation logic aggressively attempts to fetch missing RRSIG records or resolve mismatched DNSKEY records when encountering specific domain configurations. An unauthenticated remote attacker in control of a malicious domain can exploit this behavior to force the DNS server to generate excessive outbound network traffic. This can lead to resource exhaustion or a denial-of-service (DoS) state. The issue is addressed in version 15.0.
Affected products
- Technitium DNS Server Before 15.0
Timeline
- 2026-05-19: advisory: CVE-2026-45557 published by NVD/CISA
- 2026-05-19: patched: Fixed in version 15.0