Powerdns

Pdns

64 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 23.07.2026 08:03:58
  • Zuletzt bearbeitet 23.07.2026 15:48:25

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

  • EPSS 0.26%
  • Veröffentlicht 23.07.2026 08:03:37
  • Zuletzt bearbeitet 23.07.2026 15:48:25

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.

  • EPSS 0.23%
  • Veröffentlicht 23.07.2026 07:49:04
  • Zuletzt bearbeitet 23.07.2026 15:48:25

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or t...

  • EPSS 0.18%
  • Veröffentlicht 25.06.2026 13:16:45
  • Zuletzt bearbeitet 25.06.2026 16:16:35

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

  • EPSS 0.34%
  • Veröffentlicht 25.06.2026 13:01:40
  • Zuletzt bearbeitet 25.06.2026 15:59:47

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

  • EPSS 0.21%
  • Veröffentlicht 25.06.2026 13:01:08
  • Zuletzt bearbeitet 25.06.2026 15:59:47

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

  • EPSS 0.39%
  • Veröffentlicht 25.06.2026 12:59:38
  • Zuletzt bearbeitet 25.06.2026 16:16:35

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

  • EPSS 0.39%
  • Veröffentlicht 25.06.2026 12:59:16
  • Zuletzt bearbeitet 25.06.2026 16:16:35

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.

  • EPSS 0.32%
  • Veröffentlicht 25.06.2026 12:58:51
  • Zuletzt bearbeitet 25.06.2026 16:16:35

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

  • EPSS 0.12%
  • Veröffentlicht 25.06.2026 12:58:27
  • Zuletzt bearbeitet 25.06.2026 16:00:30

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.