Junglewise Threat Intelligence

CVE-2026-52690: PowerDNS Recursor DNSSEC validation failure via EDNS spoofing

CVE-2026-52690 · Severity: medium · CVSS 5.9 · Published 2026-06-25

Technologies: Powerdns Recursor. Vendors: Powerdns.

Executive brief

PowerDNS Recursor, a tool used by internet service providers to look up website addresses for users, is vulnerable to a spoofing attack. An attacker can send fake network responses that trick the system into believing a legitimate server does not support modern security standards. This results in a denial of service where secure website records (DNSSEC) fail to validate, potentially preventing users from reaching their intended destinations.

Technical details

A vulnerability in PowerDNS Recursor's outgoing EDNS handling allows a remote attacker to spoof DNS responses. By sending these malicious replies, an attacker can trick the Recursor into flagging an authoritative server's IP as lacking EDNS support. Because EDNS is required for DNSSEC, this state change causes the Recursor to fail the validation of DNSSEC records served by that authoritative server. The attack requires the adversary to successfully spoof responses (typically involving high complexity due to port and ID randomization). Patches are available in versions 5.2.11, 5.3.8, and 5.4.3.

Affected products

  • PowerDNS Recursor 5.2.0 to 5.2.10, 5.3.0 to 5.3.7, 5.4.0 to 5.4.2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats