Insufficient Name Validation in PowerDNS Software by PowerDNS
CVE-2026-42000

6.8MEDIUM

Key Information:

Vendor

Powerdns

Vendor
CVE Published:
21 May 2026

What is CVE-2026-42000?

The vulnerability involves inadequate validation of name requests during the AXFR (DNS Zone Transfer) process in PowerDNS, allowing unauthorized users to exploit this weakness. This could lead to data exposure or manipulation, as the server fails to properly verify the legitimacy of the zones being transferred.

Affected Version(s)

Authoritative 4.9.0 < 4.9.15

Authoritative 5.0.0 < 5.0.5

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ilhamaf
.