Command injection in PowerDNS Authoritative - CVE-2026-42000
Published: May 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify backend configuration.
The vulnerability exists due to command injection in Bind backend AXFR name handling when processing an AXFR of a zone with specific contents. A remote attacker can provide a zone transfer containing names with special characters to modify backend configuration.
This issue affects AXFR operations involving the Bind backend and can cause the written configuration to become non-parsable until manual correction is performed.
Affected software
Debian Linux
Fedora
pdns (Debian package)
pdns
How to mitigate CVE-2026-42000
pdns (Debian package) - update to 4.9.15-0+deb13u1
pdns - addressed in versions 5.0.5-1.el9, 5.0.5-1.el10_2, 5.0.5-1.el10_3, 5.0.5-1.fc43, 5.0.5-1.fc44