Cache Management Flaw in PowerDNS Recursor Affects ECS Configurations
CVE-2026-40012
5.3MEDIUM
What is CVE-2026-40012?
A configuration oversight in PowerDNS Recursor leads to zero scoped answers being improperly stored in the packet cache when ECS (EDNS Client Subnet) is enabled. This issue may expose sensitive network information and create potential security risks for users relying on ECS configurations.
Affected Version(s)
Recursor 5.2.0 < 5.2.11
Recursor 5.3.0 < 5.3.8
Recursor 5.4.0 < 5.4.3
