
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59024 is a DNS cache poisoning vulnerability in PowerDNS Recursor caused by insufficient verification of data authenticity (CWE-345). Crafted DNS delegations or IP fragments can be used to poison cached delegations in the Recursor, causing it to return incorrect DNS resolution data. Affected versions include PowerDNS Recursor 5.1.0–5.1.7, 5.2.0–5.2.5, and 5.3.0. The vulnerability was disclosed on February 9, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity), meaning the Recursor does not adequately validate the authenticity of DNS delegation responses or IP-fragmented DNS packets before caching them. An unauthenticated, network-based attacker can send specially crafted DNS delegation messages or fragmented IP packets that the Recursor accepts and stores in its cache without proper verification. This attack requires high complexity (e.g., timing or spoofing conditions) but no privileges or user interaction. The official security advisory is published by PowerDNS (PowerDNS Advisory, PowerDNS Blog).
Successful exploitation allows an attacker to poison the DNS cache of affected PowerDNS Recursor instances, causing clients relying on the resolver to receive fraudulent DNS responses. This can redirect users to malicious or attacker-controlled destinations, enabling phishing, credential theft, or man-in-the-middle attacks. The primary impact is high integrity loss (falsified DNS records), with a low availability impact; there is no confidentiality impact directly from this vulnerability (Red Hat Advisory, PowerDNS Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat Advisory). The EPSS score is very low at 0.005%, reflecting limited near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack complexity is rated High, requiring an attacker to meet specific conditions such as timing or network positioning to successfully inject poisoned responses.
PowerDNS has released patched versions: 5.1.8, 5.2.6, and 5.3.1, which address this vulnerability. Administrators should upgrade to one of these fixed versions immediately (PowerDNS Advisory). As additional mitigations, deploying DNSSEC validation on the Recursor can help authenticate DNS responses and reduce the risk of cache poisoning. Network access controls should be reviewed to restrict DNS query sources to trusted clients where possible, and DNS query patterns should be monitored for anomalies indicative of cache poisoning attempts (Red Hat Advisory).
The vulnerability was covered by runZero in a blog post analyzing PowerDNS Recursor security issues, and was noted in the oss-security mailing list (oss-sec). Debian issued a security advisory (DSA-6045-1) for pdns-recursor addressing this and related issues (Linux Security). Tenable published detection plugins for the vulnerability. Community reaction has been measured given the medium severity and high attack complexity, with no significant controversy or widespread alarm noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."