Input validation error in PowerDNS Recursor - CVE-2026-42389
Published: June 25, 2026
PowerDNS Recursor
Detailed vulnerability description
The vulnerability allows a remote attacker to poison the cache.
The vulnerability exists due to improper input validation in incoming answers from authoritative servers when processing crafted replies with invalid header values. A remote attacker can send spoofed crafted replies to poison the cache.
Exploitation requires massive spoofing attempts.