Powerdns

Recursor

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 09.02.2026 14:44:19
  • Zuletzt bearbeitet 20.04.2026 15:11:13

Crafted delegations or IP fragments can poison cached delegations in Recursor.

  • EPSS 0.4%
  • Veröffentlicht 09.02.2026 14:25:24
  • Zuletzt bearbeitet 20.04.2026 14:55:39

Crafted zones can lead to increased incoming network traffic.

  • EPSS 0.3%
  • Veröffentlicht 09.02.2026 14:20:46
  • Zuletzt bearbeitet 20.04.2026 14:55:46

Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

  • EPSS 0.37%
  • Veröffentlicht 09.12.2025 09:16:03
  • Zuletzt bearbeitet 07.10.2026 20:10:01

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

  • EPSS 0.55%
  • Veröffentlicht 09.12.2025 09:15:43
  • Zuletzt bearbeitet 07.10.2026 20:10:01

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

  • EPSS 0.23%
  • Veröffentlicht 21.07.2025 12:49:31
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining E...

  • EPSS 0.73%
  • Veröffentlicht 07.04.2025 13:24:17
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets can lead to an illegal memory accesses and crash of the Recursor, causing a denial of service. The remedy is: upgrade to the patch...

  • EPSS 0.7%
  • Veröffentlicht 03.10.2024 16:15:04
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of service.

  • EPSS 0.83%
  • Veröffentlicht 25.04.2024 10:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.

Medienbericht
  • EPSS 100%
  • Veröffentlicht 14.02.2024 16:15:45
  • Zuletzt bearbeitet 04.11.2025 19:16:14

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that,...