Insufficient verification of data authenticity in PowerDNS Recursor - CVE-2026-52686
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to poison the cache.
The vulnerability exists due to improper validation in the wildcard CNAME proof validation logic when processing a crafted reply from an authoritative server containing specific wildcards. A remote attacker can send a crafted reply to poison the cache.
Exploitation is limited to very specific cases outside of the attacker's control.
Affected software
Debian Linux
pdns-recursor (Debian package)
How to mitigate CVE-2026-52686
pdns-recursor (Debian package) - update to 5.2.12-0+deb13u1