Incomplete Validation Vulnerability in PowerDNS Software by PowerDNS
CVE-2026-42388

5.9MEDIUM

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-42388?

An incomplete validation issue in PowerDNS allows for potential service crashes due to improper checks of the SOA records in catalog zones. This vulnerability can disrupt operations, leading to instability and downtime for services relying on PowerDNS for DNS resolution. It is crucial for users of affected versions to apply the latest updates to ensure their DNS servers remain secure.

Affected Version(s)

Recursor 5.2.0 < 5.2.11

Recursor 5.3.0 < 5.3.8

Recursor 5.4.0 < 5.4.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.