CVE-2026-52690

MEDIUM

Spoofed answers can mark an authoritative non-EDNS capable

Title source: cna
STIX 2.1

Description

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

Scores

CVSS v3 5.9
EPSS 0.0034
EPSS Percentile 26.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (3)
PowerDNS/Recursor 5.2.0 - 5.2.11
PowerDNS/Recursor 5.3.0 - 5.3.8
PowerDNS/Recursor 5.4.0 - 5.4.3
Published Jun 25, 2026
Tracked Since Jun 25, 2026