TCP Proxy Request Mismanagement in PowerDNS by PowerDNS
CVE-2026-41999

4.8MEDIUM

Key Information:

Vendor

Powerdns

Vendor
CVE Published:
21 May 2026

What is CVE-2026-41999?

This vulnerability involves a flaw in the handling of TCP proxy requests within the PowerDNS Authoritative Server, which could lead to unexpected behavior and potentially allow unauthorized access to sensitive data. Affected users must apply the necessary patches to mitigate these risks and ensure the integrity and security of their DNS infrastructure.

Affected Version(s)

Authoritative 5.0.0 < 5.0.5

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zwique
.