Powerdns recursor
This hub aggregates every CVE we track for Powerdns recursor, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
1
Critical
5
High
0
In CISA KEV
Severity distribution
MEDIUM8HIGH5LOW1CRITICAL1
Monthly trend
1
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
4
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Powerdns recursor.
- CVE-2025-59024Crafted delegations or IP fragments can poison cached delegations in Recursor6.5
- CVE-2025-59023Crafted delegations or IP fragments can poison cached delegations in Recursor8.2
- CVE-2026-24027Crafted zones can lead to increased incoming network traffic5.3
- CVE-2026-0398Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor5.3
- CVE-2025-30192A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempts7.5
- CVE-2024-25590Crafted responses can lead to a denial of service due to cache inefficiencies in the Recursor7.5
- CVE-2023-26437Deterred spoofing attempts can lead to authoritative servers being marked unavailable3.4
- CVE-2020-12244An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, all...7.5
- CVE-2017-15094An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys ar...5.9
- CVE-2017-15092A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowi...6.1
- CVE-2017-15093When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized ...5.3
- CVE-2014-3614Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.5.0
- CVE-2012-1193The resolver in PowerDNS Recursor (aka pdns_recursor) 3.3 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote a...6.4
- CVE-2009-4010Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.7.5
- CVE-2009-4009Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets.10.0
Product normalization is registry-driven with AI assist and human review. How it works