CVE-2025-59023
- EPSS 0.01%
- Veröffentlicht 09.02.2026 14:44:19
- Zuletzt bearbeitet 20.04.2026 15:11:13
Crafted delegations or IP fragments can poison cached delegations in Recursor.
CVE-2026-24027
- EPSS 0.01%
- Veröffentlicht 09.02.2026 14:25:24
- Zuletzt bearbeitet 20.04.2026 14:55:39
Crafted zones can lead to increased incoming network traffic.
CVE-2026-0398
- EPSS 0.01%
- Veröffentlicht 09.02.2026 14:20:46
- Zuletzt bearbeitet 20.04.2026 14:55:46
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
CVE-2025-59029
- EPSS 0.01%
- Veröffentlicht 09.12.2025 09:16:03
- Zuletzt bearbeitet 19.02.2026 17:13:48
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
CVE-2025-59030
- EPSS 0.08%
- Veröffentlicht 09.12.2025 09:15:43
- Zuletzt bearbeitet 19.02.2026 17:04:30
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
CVE-2025-30192
- EPSS 0.05%
- Veröffentlicht 21.07.2025 12:49:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining E...
CVE-2025-30195
- EPSS 0.04%
- Veröffentlicht 07.04.2025 13:24:17
- Zuletzt bearbeitet 15.04.2026 00:35:42
An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patch...
CVE-2024-25590
- EPSS 0.13%
- Veröffentlicht 03.10.2024 16:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.
CVE-2024-25583
- EPSS 0.01%
- Veröffentlicht 25.04.2024 10:15:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.
CVE-2023-50868
- EPSS 11.8%
- Veröffentlicht 14.02.2024 16:15:45
- Zuletzt bearbeitet 23.12.2025 20:20:08
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka...