PowerDNS Recursor NSEC Cache Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in PowerDNS Recursor. By publishing and querying a specially crafted zone, an attacker can cause the allocation of large entries in the negative and aggressive NSEC(3) caches, potentially leading to performance degradation.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition by degrading the performance of the PowerDNS Recursor, likely leading to increased response times or service interruptions.

Added: Apr 22, 2026, 11:22 AM
Updated: Apr 22, 2026, 11:22 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
0.6
exploitability
7.0
remediation
0.0
relevance
6.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.