Invalid Zone Bypass in PowerDNS Recursor
CVE-2026-42390
5.3MEDIUM
What is CVE-2026-42390?
An invalid zone may incorrectly pass ZONEMD validation checks in PowerDNS Recursor when ZoneToCache is set with ZONEMD validation mode enabled. This flaw could potentially be exploited in configurations relying on accurate validation for zone caching, compromising DNS integrity.
Affected Version(s)
Recursor 5.4.0 < 5.4.3
