PowerDNS maintains a focused but widely deployed suite of DNS infrastructure software, including its Recursor, Authoritative Server, and DNSDist load balancer, that sits at the network boundary of organizations globally. Despite the concentrated product portfolio, the vendor appears in the landscape at significant prevalence due to the mission-critical role DNS resolution plays in internet operations and the broad adoption of its open-source offerings. Vulnerabilities affecting PowerDNS recur through input-validation and resource-consumption weakness classes—reflective of the parsing and state-management demands inherent to authoritative and recursive DNS resolution—with a meaningful tendency toward serious severity outcomes. Defenders should inventory PowerDNS deployments across authoritative, recursive, and load-balancing roles, as flaws in DNS infrastructure can cascade widely; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Powerdns over time
Signals from CVEs in this vendor scope (126 CVEs).
126 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50387HIGH Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D | Feb 14, 2024 | 7.5 | 78 | NO | NO |
CVE-2023-50868HIGH The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA- | Feb 14, 2024 | 7.5 | 72 | NO | NO |
CVE-2021-36754HIGH PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception. | Jul 30, 2021 | 7.5 | 71 | NO | YES |
CVE-2015-1868HIGH The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x be | May 18, 2015 | 7.8 | 63 | NO | NO |
CVE-2016-5427HIGH PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU con | Sep 21, 2016 | 7.5 | 59 | NO | NO |
CVE-2018-16855HIGH An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of t | Dec 3, 2018 | 7.5 | 57 | NO | NO |
CVE-2014-8601MEDIUM PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite n | Dec 10, 2014 | 5.0 | 56 | NO | NO |
CVE-2015-5311MEDIUM PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets. | Nov 17, 2015 | 5.0 | 54 | NO | NO |
CVE-2017-15120HIGH An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer con | Jul 27, 2018 | 7.5 | 53 | NO | NO |
CVE-2016-5426HIGH PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname. | Sep 21, 2016 | 7.5 | 40 | NO | NO |
Signals from CVEs in this vendor scope (126 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Powerdns.
Media articles that mention a CVE ID that affects a product developed by Powerdns — matched by CVE ID, not by vendor name.