Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-42389: Improper Input Validation in PowerDNS Recursor

0
Medium
VulnerabilityCVE-2026-42389cvecve-2026-42389
Published: 06/25/2026 (06/25/2026, 13:16:45 UTC)
Source: CVE Database V5
Vendor/Project: PowerDNS
Product: Recursor

Description

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

CVSS v3.1

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected software

GitHub Actionsmore threats →cve
pdns-recursor
pkg:github/pdns-recursor
Affected versions
>=5.4.0 <5.4.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/25/2026, 14:47:27 UTC

Technical Analysis

This vulnerability in PowerDNS Recursor affects versions 5.4.0 up to but not including 5.4.3. It involves improper input validation of DNS answers received from authoritative servers. The vulnerability does not impact confidentiality or availability but may allow integrity issues due to malformed or malicious responses. The vendor has addressed the issue by adding extra validation hardening in the 5.4.x branch. No explicit patch or remediation level is stated in the available data, but the description indicates a fix exists in versions after 5.4.0 and before 5.4.3.

Potential Impact

The vulnerability has a CVSS 3.1 base score of 5.3 (medium severity), indicating a network attack vector with low complexity and no privileges or user interaction required. The impact is limited to integrity (I:L), with no confidentiality or availability impact. This suggests that an attacker could potentially influence or tamper with DNS responses processed by the recursor, but cannot cause denial of service or data disclosure.

Mitigation Recommendations

A fix is available as indicated by the vendor's note of extra validation hardening in the 5.4.x branch. Users should upgrade to PowerDNS Recursor version 5.4.3 or later to ensure the vulnerability is addressed. Patch status is not explicitly confirmed in the advisory, so users should verify the vendor's official release notes or advisories for the exact fixed version and apply updates accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
OX
Date Reserved
2026-04-27T08:53:58.839Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a3d38354853345fc10a3535

Added to database: 06/25/2026, 14:16:21 UTC

Last enriched: 06/25/2026, 14:47:27 UTC

Last updated: 06/25/2026, 23:21:26 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses