PowerDNS Recursor Denial-of-Service Vulnerability via Crafted Zones

Vulnerability

A denial-of-service vulnerability has been identified in PowerDNS Recursor version 5.2.0. An attacker can publish a zone with specific Resource Record Sets, which, when processed and cached, can lead to illegal memory accesses. This causes the Recursor to crash, disrupting service. PowerDNS Recursor 5.2.1 and versions prior to 5.2.0 are not affected.

Impact

Exploitation of this vulnerability leads to a crash of the PowerDNS Recursor, causing a denial-of-service condition.

Remediation

Users are advised to upgrade to PowerDNS Recursor version 5.2.1, which addresses this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.