SB2026062580 - Denial of service in PowerDNS Authoritative Server



SB2026062580 - Denial of service in PowerDNS Authoritative Server

Published: June 25, 2026

Security Bulletin ID SB2026062580
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-42005)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote client to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the internal web server when handling crafted HTTP queries. A remote client can send a crafted HTTP request to cause a denial of service.

The issue can only be triggered if the internal web server is enabled, and the internal web server is disabled by default.


Remediation

Install update from vendor's website.