Allocation of Resources Without Limits or Throttling in PowerDNS Authoritative - CVE-2026-42005

 

Allocation of Resources Without Limits or Throttling in PowerDNS Authoritative - CVE-2026-42005

Published: June 25, 2026 / Updated: June 25, 2026


Vulnerability identifier: #VU135238
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42005
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote client to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the internal web server when handling crafted HTTP queries. A remote client can send a crafted HTTP request to cause a denial of service.

The issue can only be triggered if the internal web server is enabled, and the internal web server is disabled by default.


Affected software

PowerDNS Authoritative
PowerDNS Recursor
Debian Linux
Fedora
dnsdist
dnsdist (Debian package)
pdns (Debian package)
pdns
pdns-recursor (Debian package)

How to mitigate CVE-2026-42005

Install security update from vendor's website.

PowerDNS Authoritative - addressed in versions 4.9.16, 5.0.6, 5.1.2
dnsdist - addressed in versions 1.9.15, 2.0.7
PowerDNS Recursor - update to 5.2.11
dnsdist (Debian package) - update to 1.9.15-0+deb13u1
pdns (Debian package) - update to 4.9.16-0+deb13u1
pdns - addressed in versions 5.0.6-1.el9, 5.0.6-1.el10_2, 5.0.6-1.el10_3, 5.0.6-1.fc43, 5.0.6-1.fc44
pdns-recursor (Debian package) - update to 5.2.11-0+deb13u1

External References

Related Security Bulletins