Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/pdns-recursor

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

Join the discussion

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.

Join the discussion

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.

Join the discussion

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

Join the discussion

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

Join the discussion

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

Join the discussion

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

Join the discussion

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.

Join the discussion

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

Join the discussion

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.

Join the discussion

Showing 1 to 10 of 23 results

Filters:Package: pkg:github/pdns-recursor
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses