Code Injection in PowerDNS Authoritative - CVE-2026-42396
Published: May 20, 2026
PowerDNS Authoritative
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to code injection in catalog zone label computation when processing an AXFR of a catalog zone with a member whose producer group option contains a double-quote character. A remote privileged user can provide catalog zone member data containing a double-quote character to cause a denial of service.
This issue causes the catalog zone transfer to fail.