📦

recursor

Vendor: powerdns

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 3 Remote Access
Total CVEs 86 Total Indexed
Avg. EPSS 11.91% Exploit Prob.
Latest CVE CVE-2026-33601 Apr 22

Security Vulnerability Index

Page 2 / 9
5.3 CVSS

Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

EPSS: 0.30%
6.5 CVSS

Crafted delegations or IP fragments can poison cached delegations in Recursor.

EPSS: 0.12%
8.2 CVSS

Crafted delegations or IP fragments can poison cached delegations in Recursor.

EPSS: 0.27%
7.5 CVSS

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

EPSS: 0.52%
5.3 CVSS

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

EPSS: 0.34%
7.5 CVSS
CVE-2023-50868
Exploit Found

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

EPSS: 81.73%
7.5 CVSS
CVE-2023-50387
RCE Exploit Found

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

EPSS: 99.99%
3.4 CVSS

Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.

EPSS: 0.59%
7.5 CVSS

A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured domain, because QName minimization is used in QM fallback mode. This is fixed in 4.8.1.

EPSS: 7.32%
6.5 CVSS

PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.

EPSS: 1.19%