Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Powerdns

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 126
47.5
VTI Score
High

PowerDNS maintains a focused but widely deployed suite of DNS infrastructure software, including its Recursor, Authoritative Server, and DNSDist load balancer, that sits at the network boundary of organizations globally. Despite the concentrated product portfolio, the vendor appears in the landscape at significant prevalence due to the mission-critical role DNS resolution plays in internet operations and the broad adoption of its open-source offerings. Vulnerabilities affecting PowerDNS recur through input-validation and resource-consumption weakness classes—reflective of the parsing and state-management demands inherent to authoritative and recursive DNS resolution—with a meaningful tendency toward serious severity outcomes. Defenders should inventory PowerDNS deployments across authoritative, recursive, and load-balancing roles, as flaws in DNS infrastructure can cascade widely; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
126
Total CVEs
More Total CVEs than 99% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 40% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Powerdns over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (126 CVEs).

126 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-50387HIGH
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D
Feb 14, 20247.578NONO
CVE-2023-50868HIGH
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-
Feb 14, 20247.572NONO
CVE-2021-36754HIGH
PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.
Jul 30, 20217.571NOYES
CVE-2015-1868HIGH
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x be
May 18, 20157.863NONO
CVE-2016-5427HIGH
PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU con
Sep 21, 20167.559NONO
CVE-2018-16855HIGH
An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of t
Dec 3, 20187.557NONO
CVE-2014-8601MEDIUM
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite n
Dec 10, 20145.056NONO
CVE-2015-5311MEDIUM
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
Nov 17, 20155.054NONO
CVE-2017-15120HIGH
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer con
Jul 27, 20187.553NONO
CVE-2016-5426HIGH
PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.
Sep 21, 20167.540NONO
View all 126 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products126 CVEs
45%
45%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.8%)
Network103 (81.7%)
Unknown20 (15.9%)
Physical0 (0.0%)
Adjacent Network2 (1.6%)
Attack Complexity
Low79 (62.7%)
High27 (21.4%)
Unknown20 (15.9%)
User Interaction
None101 (80.2%)
Unknown20 (15.9%)
Required5 (4.0%)
Privileges Required
Low12 (9.5%)
High4 (3.2%)
None90 (71.4%)
Unknown20 (15.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (126 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.8% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Powerdns.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Powerdns — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Powerdns's Products

View all 4 CNAs →

Top CWEs