Authentication Bypass by Spoofing in PowerDNS Recursor - CVE-2026-52690
Published: June 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to authentication bypass by spoofing in EDNS capability tracking for authoritative servers when processing spoofed replies. A remote attacker can spoof replies to cause a denial of service.
The issue can cause DNSSEC validation of zones served by the targeted authoritative server to fail.
Affected software
Debian Linux
pdns-recursor (Debian package)
How to mitigate CVE-2026-52690
pdns-recursor (Debian package) - update to 5.2.11-0+deb13u1