Allocation of Resources Without Limits or Throttling in PowerDNS Authoritative - CVE-2026-42005
Published: June 25, 2026 / Updated: June 25, 2026
PowerDNS Authoritative
Detailed vulnerability description
The vulnerability allows a remote client to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the internal web server when handling crafted HTTP queries. A remote client can send a crafted HTTP request to cause a denial of service.
The issue can only be triggered if the internal web server is enabled, and the internal web server is disabled by default.