Allocation of Resources Without Limits or Throttling in PowerDNS Authoritative - CVE-2026-42005
Published: June 25, 2026 / Updated: June 25, 2026
Vulnerability details
The vulnerability allows a remote client to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the internal web server when handling crafted HTTP queries. A remote client can send a crafted HTTP request to cause a denial of service.
The issue can only be triggered if the internal web server is enabled, and the internal web server is disabled by default.
Affected software
PowerDNS Recursor
Debian Linux
Fedora
dnsdist
dnsdist (Debian package)
pdns (Debian package)
pdns
pdns-recursor (Debian package)
How to mitigate CVE-2026-42005
dnsdist - addressed in versions 1.9.15, 2.0.7
PowerDNS Recursor - update to 5.2.11
dnsdist (Debian package) - update to 1.9.15-0+deb13u1
pdns (Debian package) - update to 4.9.16-0+deb13u1
pdns - addressed in versions 5.0.6-1.el9, 5.0.6-1.el10_2, 5.0.6-1.el10_3, 5.0.6-1.fc43, 5.0.6-1.fc44
pdns-recursor (Debian package) - update to 5.2.11-0+deb13u1
External References
Related Security Bulletins
- Denial of service in PowerDNS Authoritative Server
- Multiple vulnerabilities in PowerDNS DNSdist
- Multiple vulnerabilities in PowerDNS Recursor
- Fedora 44 update for pdns
- Fedora EPEL 10.2 update for pdns
- Fedora EPEL 10.3 update for pdns
- Fedora 43 update for pdns
- Debian update for pdns-recursor
- Debian update for pdns
- Debian update for dnsdist
- Fedora EPEL 9 update for pdns