
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0398 is a dual-nature vulnerability in PowerDNS Recursor that allows unauthenticated remote attackers to cause increased resource consumption via crafted DNS zones and to perform cache poisoning via crafted CNAME chains. It was published on February 9, 2026, and affects PowerDNS Recursor versions 5.1.0 through 5.1.9, 5.2.x through 5.2.7, and 5.3.0 through 5.3.4. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium), though Feedly's category estimate rates it as HIGH given its network-accessible, no-authentication-required nature (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), where PowerDNS Recursor fails to adequately constrain resource consumption when processing specially crafted DNS zones. A second attack vector involves crafted CNAME chains that can manipulate the resolver's cache, resulting in cache poisoning. Both attack vectors are exploitable over the network without authentication or user interaction, making them accessible to any attacker who can send DNS queries to the resolver. The PowerDNS security advisory (2026-01) provides the authoritative technical description of both issues (PowerDNS Advisory, PowerDNS Blog).
Exploitation of the resource exhaustion vector can degrade or disrupt DNS resolution services, causing availability issues for all downstream clients relying on the affected Recursor instance. The cache poisoning vector via crafted CNAME chains can cause DNS clients to receive incorrect or malicious DNS records, potentially redirecting traffic to attacker-controlled infrastructure and enabling man-in-the-middle attacks or phishing scenarios. Confidentiality and integrity of DNS responses are at risk from the cache poisoning component, while availability is at risk from the resource exhaustion component (Red Hat Advisory, Red Hat Bugzilla).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat Advisory). The EPSS score is very low at 0.01%, reflecting limited current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (IDs 298462 and 299057) and Qualys (ID 692218), indicating scanner coverage for affected deployments.
pdns_recursor process without a corresponding increase in legitimate query load.PowerDNS has released patched versions addressing CVE-2026-0398: upgrade to Recursor 5.1.10, 5.2.8, or 5.3.5 or later as appropriate for your branch (PowerDNS Advisory). As interim mitigations, administrators should implement network-level access controls to restrict DNS queries to trusted sources only, apply rate limiting on queries from untrusted sources, and monitor Recursor instances for unusual resource consumption or cache anomalies. A Debian security advisory (DSA-6134-1) has also been issued for package maintainers (Linux Security).
PowerDNS published a security advisory blog post on February 9, 2026, coinciding with the CVE disclosure (PowerDNS Blog). Red Hat tracked the issue via Bugzilla and issued a security advisory, and Debian issued DSA-6134-1 for the pdns-recursor package. The vulnerability was discussed on the oss-security mailing list shortly after disclosure (oss-sec). No significant social media controversy or notable independent researcher commentary has been observed beyond standard vulnerability aggregator coverage.
Fix availability across major Linux distributions and their releases.
bookworm
pdns-recursor
sid
pdns-recursor: 5.3.5-1
trixie
pdns-recursor: 5.2.8-0+deb13u1
bionic (esm-apps)
pdns-recursor
devel
pdns-recursor
focal (esm-apps)
pdns-recursor
jammy
pdns-recursor
jammy (esm-apps)
pdns-recursor
noble
pdns-recursor
noble (esm-apps)
pdns-recursor
resolute
pdns-recursor
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."