Insufficient verification of data authenticity in PowerDNS Recursor - CVE-2026-52686
Published: July 22, 2026
PowerDNS Recursor
Detailed vulnerability description
The vulnerability allows a remote attacker to poison the cache.
The vulnerability exists due to improper validation in the wildcard CNAME proof validation logic when processing a crafted reply from an authoritative server containing specific wildcards. A remote attacker can send a crafted reply to poison the cache.
Exploitation is limited to very specific cases outside of the attacker's control.