DNSSEC Validation Bypass in PowerDNS Recursor
CVE-2026-52686
3.7LOW
What is CVE-2026-52686?
This vulnerability involves a DNSSEC validation bypass where the system erroneously accepts wildcard expansion proofs, specifically NSEC and NSEC3 records, without necessary signature validation when the wildcard answer corresponds to a CNAME or DNAME record. Such bypasses can potentially allow unauthorized information disclosure or enable further attacks on the DNS structure.
Affected Version(s)
Recursor 5.2.0 < 5.2.12
Recursor 5.3.0 < 5.3.9
Recursor 5.4.0 < 5.4.4
