CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-52688HIGH | RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationRRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation | CVSS7.5v3.1 | EPSS0.127% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Wildcard CNAME proof validation bypassThe issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record. CWE-347Jul 23, 2026 | CVSS3.7v3.1 | EPSS0.113% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning AttackIf the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records. Jul 23, 2026 | CVSS3.7v3.1 | EPSS0.143% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-42389MEDIUM | Reject more queries with invalid header valuesThis fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers. CWE-20Jun 25, 2026 | CVSS5.3v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-52690MEDIUM | Spoofed answers can mark an authoritative non-EDNS capableSpoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail. CWE-290Jun 25, 2026 | CVSS5.9v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42390MEDIUM | ZONEMD validation can be bypassedAn invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation. CWE-20Jun 25, 2026 | CVSS5.3v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42388MEDIUM | Missing input validation for catalog zonesIncomplete validation of the SOA record present in a catalog zone might lead to a crash. CWE-20Jun 25, 2026 | CVSS5.9v3.1 | EPSS0.386% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-42387MEDIUM | Insufficient input validation in ZoneToCacheA malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation. CWE-20Jun 25, 2026 | CVSS5.9v3.1 | EPSS0.386% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-40012MEDIUM | Information about ECS zero scoped answers might leak to clients that use a specific ECSECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled; CWE-524Jun 25, 2026 | CVSS5.3v3.1 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33612HIGH | ZoneToCache can poison the cacheA malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning. CWE-349Jun 25, 2026 | CVSS7.5v3.1 | EPSS0.115% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33262MEDIUM | Insufficient validation of cookie replyAn attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default. CWE-476Apr 22, 2026 | CVSS5.9v3.1 | EPSS0.418% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33261MEDIUM | Null pointer accces in aggressive NSEC(3) cacheA zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service. CWE-353Apr 22, 2026 | CVSS5.9v3.1 | EPSS0.228% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33260MEDIUM | Insufficient input validation of internal webserverAn attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. CWE-770Apr 22, 2026 | CVSS5.3v3.1 | EPSS0.524% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33259MEDIUM | Concurrent modification of RPZ data can lead to denial of servceHaving many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider. CWE-416Apr 22, 2026 | CVSS5.0v3.1 | EPSS0.225% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33258MEDIUM | Crafted zones can cause increased resource usageBy publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches. CWE-770Apr 22, 2026 | CVSS5.3v3.1 | EPSS0.583% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33257MEDIUM | Insufficient input validation of internal webserverAn attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. CWE-770Apr 22, 2026 | CVSS5.3v3.1 | EPSS0.514% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33256MEDIUM | Unbounded memory allocation by internal web serverAn attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default. CWE-770Apr 22, 2026 | CVSS5.3v3.1 | EPSS0.606% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33601MEDIUM | Insufficient validation of zonemd recordIf you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. CWE-476Apr 22, 2026 | CVSS4.4v3.1 | EPSS0.512% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-33600MEDIUM | Null pointer dereference in RPZ transferAn RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. CWE-476Apr 22, 2026 | CVSS4.4v3.1 | EPSS0.523% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59024MEDIUM | Crafted delegations or IP fragments can poison cached delegations in RecursorCrafted delegations or IP fragments can poison cached delegations in Recursor. CWE-345Feb 9, 2026 | CVSS6.5v3.1 | EPSS0.122% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59023HIGH | Crafted delegations or IP fragments can poison cached delegations in RecursorCrafted delegations or IP fragments can poison cached delegations in Recursor. CWE-294Feb 9, 2026 | CVSS8.2v3.1 | EPSS0.266% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24027MEDIUM | Crafted zones can lead to increased incoming network trafficCrafted zones can lead to increased incoming network traffic. CWE-294Feb 9, 2026 | CVSS5.3v3.1 | EPSS0.396% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0398MEDIUM | Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in RecursorCrafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor. CWE-770Feb 9, 2026 | CVSS5.3v3.1 | EPSS0.303% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59029MEDIUM | Internal logic flaw in cache management can lead to a denial of service in PowerDNS RecursorAn attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY. CWE-617Dec 9, 2025 | CVSS5.3v3.1 | EPSS0.369% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59030HIGH | Insufficient validation of incoming notifies over TCP can lead to a denial of service in RecursorAn attacker can trigger the removal of cached records by sending a NOTIFY query over TCP. CWE-276Dec 9, 2025 | CVSS7.5v3.1 | EPSS0.553% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |