3.7
CVE-2026-52684
- EPSS 0.14%
- Veröffentlicht 23.07.2026 07:49:04
- Zuletzt bearbeitet 23.07.2026 15:48:25
- CVE-Watchlists
- Unerledigt
Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack
If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPowerDNS
≫
Produkt
Recursor
Default Statusunaffected
Version
0.0.0
Version <
5.5.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.04 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@open-xchange.com | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
|
https://github.com/PowerDNS/pdns/pull/17748