Home

Description

Crafted delegations or IP fragments can poison cached delegations in Recursor.

PUBLISHED Reserved 2025-09-08 | Published 2026-02-09 | Updated 2026-02-09 | Assigner OX




HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

Problem types

Insufficient Verification of Data Authenticity

Product status

Default status
unaffected

5.3.0 (semver) before 5.3.1
affected

5.2.0 (semver) before 5.2.6
affected

5.1.0 (semver) before 5.1.8
affected

Credits

Yuxiao Wu from Tsinghua University finder

Yunyi Zhang from Tsinghua University finder

Baojun Liu from Tsinghua University finder

Haixin Duan from Tsinghua University finder

Shiming Liu from Network and Information Security Lab, Tsinghua University finder

References

docs.powerdns.com/...visories/powerdns-advisory-2025-06.html

cve.org (CVE-2025-59023)

nvd.nist.gov (CVE-2025-59023)

Download JSON