
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59030 is a cache invalidation vulnerability in PowerDNS Recursor that allows an unauthenticated remote attacker to remove cached DNS records by sending a NOTIFY query over TCP. It affects PowerDNS Recursor versions 5.1.0–5.1.8, 5.2.0–5.2.6, and 5.3.0–5.3.2. The vulnerability was published on December 9, 2025, with patches released concurrently. It carries a CVSS v3.1 base score of 7.5 (High) (PowerDNS Advisory, ENISA EUVD).
The vulnerability is classified under CWE-276 (Incorrect Default Permissions), indicating that the PowerDNS Recursor improperly handles NOTIFY queries received over TCP without enforcing appropriate access controls. Under normal DNS operation, NOTIFY messages are used by authoritative servers to signal zone changes to secondary servers; however, in this case, the Recursor incorrectly processes such queries and triggers the eviction of cached records. No authentication or special privileges are required, and the attack vector is network-accessible with low complexity. The flaw allows any remote host to manipulate the resolver's cache state by crafting and sending TCP-based NOTIFY packets (PowerDNS Advisory, PowerDNS Blog).
Successful exploitation degrades DNS resolution performance by forcing the Recursor to re-resolve records that were previously cached, resulting in a denial-of-service condition for dependent systems and services. Additionally, cache invalidation can open a window for DNS poisoning attacks, where an attacker could attempt to inject malicious records after flushing legitimate ones. There is no confidentiality or integrity impact on the resolver itself, but downstream services relying on cached DNS responses may experience disruption or be exposed to spoofed DNS responses (PowerDNS Advisory, ENISA EUVD).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (ENISA EUVD). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.021%, reflecting a low probability of exploitation in the near term. Despite the low exploitation evidence, the attack requires no authentication and has low complexity, making it trivially executable by any network-accessible attacker.
Upgrade PowerDNS Recursor to the patched versions: 5.1.9 or later (for 5.1.x deployments), 5.2.7 or later (for 5.2.x deployments), or 5.3.3 or later (for 5.3.x deployments). As a network-level workaround where immediate patching is not feasible, restrict TCP access to port 53 on the Recursor to only trusted authoritative name servers using firewall rules or ACLs. Monitor for unusual cache invalidation patterns and DNS query anomalies as an interim detection measure (PowerDNS Advisory, PowerDNS Blog).
PowerDNS published a security advisory and blog post on December 8–9, 2025, disclosing the vulnerability alongside a companion advisory (2025-07). The issue was also disclosed via the oss-security mailing list and picked up by Linux distribution security channels including Debian and Fedora, which issued updated packages (oss-sec, Linux Security). Tenable released Nessus detection plugins (IDs 277742 and 278085) shortly after disclosure (Tenable).
Fix availability across major Linux distributions and their releases.
bookworm
pdns-recursor
sid
pdns-recursor: 5.3.3-1
trixie
pdns-recursor: 5.2.7-0+deb13u1
bionic (esm-apps)
pdns-recursor
devel
pdns-recursor
focal (esm-apps)
pdns-recursor
jammy
pdns-recursor
jammy (esm-apps)
pdns-recursor
noble
pdns-recursor
noble (esm-apps)
pdns-recursor
resolute
pdns-recursor
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."