Authentication Bypass by Spoofing in PowerDNS Recursor - CVE-2026-52690
Published: June 25, 2026
PowerDNS Recursor
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to authentication bypass by spoofing in EDNS capability tracking for authoritative servers when processing spoofed replies. A remote attacker can spoof replies to cause a denial of service.
The issue can cause DNSSEC validation of zones served by the targeted authoritative server to fail.