
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59029 is a Reachable Assertion (CWE-617) vulnerability in PowerDNS Recursor that allows unauthenticated remote attackers to trigger a denial of service by crashing the DNS service. It affects PowerDNS Recursor versions 5.3.0 and 5.3.1. The vulnerability was published on December 9, 2025, with a patch available in version 5.3.2. It carries a CVSS v3.1 base score of 5.3 (Medium) (PowerDNS Advisory, ENISA EUVD).
The vulnerability is classified as CWE-617 (Reachable Assertion), meaning an attacker can cause the application to reach an internal assertion check that fails, resulting in an abnormal process termination. The attack is a two-stage process: first, the attacker sends crafted DNS records to the resolver, waits for those records to be inserted into the Recursor's record cache, and then sends a follow-up DNS query with the query type (qtype) set to ANY. This combination triggers an assertion failure within the Recursor process, causing it to crash. No authentication, privileges, or user interaction are required, and the attack is executable over the network with low complexity (PowerDNS Advisory, ENISA EUVD).
Successful exploitation crashes the PowerDNS Recursor process, causing a complete loss of DNS resolution availability for all clients relying on the affected resolver. The impact is limited to availability — there is no confidentiality or integrity impact. Organizations depending on the affected Recursor instances for DNS infrastructure could experience service outages affecting all downstream systems and users until the service is restarted or failover occurs (PowerDNS Advisory, ENISA EUVD).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.012%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (ENISA EUVD, PowerDNS Advisory).
qtype=ANY.qtype set to ANY for the cached domain. The Recursor processes the cached crafted records in response to the ANY query, hits the internal assertion check, and crashes.qtype=ANY directed at the Recursor; DNS queries for uncommon or newly registered domains followed shortly by ANY queries for the same domains.pdns_recursor process without administrative action; monitoring alerts for Recursor service restarts.The primary remediation is to upgrade PowerDNS Recursor to version 5.3.2 or later, which contains the fix for this assertion failure. Only versions 5.3.0 and 5.3.1 are affected; organizations running earlier versions in other branches are not impacted by this specific CVE. No configuration-based workaround has been published; upgrading is the recommended and only confirmed mitigation (PowerDNS Advisory, PowerDNS Blog).
PowerDNS published a security advisory and blog post on December 8–9, 2025, disclosing the vulnerability alongside advisory 2025-08. The disclosure was also reported to the oss-security mailing list, following standard coordinated disclosure practices. Coverage has been limited to security aggregators and Linux distribution security channels, with Fedora issuing updates for affected packages in 2026 (PowerDNS Blog, oss-sec).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
pdns-recursor
devel
pdns-recursor
focal (esm-apps)
pdns-recursor
jammy
pdns-recursor
jammy (esm-apps)
pdns-recursor
noble
pdns-recursor
noble (esm-apps)
pdns-recursor
resolute
pdns-recursor
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."