
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-52682 is a resource exhaustion vulnerability affecting PowerDNS Authoritative Server, Recursor, and dnsdist, in which a crafted DNS packet can cause increased memory and CPU consumption. The CVE was reserved and first disclosed via a PowerDNS security advisory on August 6, 2026, with subsequent coverage on oss-sec and Tenable/Nessus detection plugins. The estimated CVSS severity is Medium (PowerDNS Advisory, Feedly).
The vulnerability is rooted in improper handling of specially crafted DNS packets, leading to excessive memory and CPU consumption — consistent with CWE-400 (Uncontrolled Resource Consumption). An attacker can send a malformed or crafted DNS query to an affected PowerDNS component (Authoritative Server, Recursor, or dnsdist), triggering disproportionate resource usage. No authentication is required, as DNS services are typically exposed to untrusted network traffic. Specific technical details such as the exact packet structure or code path involved have not yet been publicly disclosed beyond the vendor advisory (PowerDNS Advisory, oss-sec).
Successful exploitation can degrade or deny DNS resolution services by exhausting memory and CPU resources on affected PowerDNS instances. This affects availability of DNS infrastructure, which can cascade to broader service outages for any systems relying on the affected resolver or authoritative server. Confidentiality and integrity are not directly impacted, but a sustained denial-of-service condition could be leveraged as part of a larger attack chain (PowerDNS Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability is network-accessible and requires no authentication, lowering the barrier for exploitation. EPSS score and CISA KEV catalog status are not yet available for this CVE. Nessus detection plugins (IDs 333190 and 333498) have been released to identify vulnerable systems (Tenable Nessus 333190, Tenable Nessus 333498).
pdns_server, pdns_recursor, dnsdist).pdns_server, pdns_recursor, or dnsdist processes consuming abnormally high system resources as observed via top, htop, or system monitoring tools (PowerDNS Advisory).Users should apply the patches released by PowerDNS as detailed in the security advisory published on August 6, 2026, which addresses this issue across the Authoritative Server, Recursor, and dnsdist. FreeBSD ports for powerdns-recursor have also been updated. As a temporary workaround, consider rate-limiting inbound DNS queries at the network perimeter or firewall to reduce exposure to crafted packet attacks. Monitor the official PowerDNS advisory for specific patched version numbers and any additional workaround guidance (PowerDNS Advisory, FreeBSD Ports).
The vulnerability was disclosed via the oss-sec mailing list shortly after the PowerDNS advisory, indicating standard coordinated disclosure practices. Tenable released multiple Nessus and container security plugins within days of disclosure, reflecting prompt detection tooling response. No notable researcher commentary or significant social media discussion has been identified beyond standard security community monitoring (oss-sec, Tenable Nessus 333190).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."