Input validation error in PowerDNS Recursor - CVE-2026-42389
Published: June 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to poison the cache.
The vulnerability exists due to improper input validation in incoming answers from authoritative servers when processing crafted replies with invalid header values. A remote attacker can send spoofed crafted replies to poison the cache.
Exploitation requires massive spoofing attempts.