Insufficient Name Validation in PowerDNS Software by PowerDNS
CVE-2026-42000
6.8MEDIUM
What is CVE-2026-42000?
The vulnerability involves inadequate validation of name requests during the AXFR (DNS Zone Transfer) process in PowerDNS, allowing unauthorized users to exploit this weakness. This could lead to data exposure or manipulation, as the server fails to properly verify the legitimacy of the zones being transferred.
Affected Version(s)
Authoritative 4.9.0 < 4.9.15
Authoritative 5.0.0 < 5.0.5
