Concurrency and Locking Defects in PowerDNS by PowerDNS
CVE-2026-42002

5.9MEDIUM

Key Information:

Vendor

Powerdns

Vendor
CVE Published:
21 May 2026

What is CVE-2026-42002?

PowerDNS has been found to have concurrency and locking defects in its GSS-TSIG implementation. These defects can lead to unexpected behaviors under certain conditions, potentially affecting the integrity and availability of DNS services. Addressing these vulnerabilities is crucial to fortifying the reliability of DNS operations and maintaining system security.

Affected Version(s)

Authoritative 4.9.0 < 4.9.15

Authoritative 5.0.0 < 5.0.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thanos_haruki
.