CVE-2019-3806: Powerdns Recursor
High severity, CVSS 8.1. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.
Affected products
- Powerdns Recursor: from 4.1.4, before 4.1.9 (fixed in 4.1.9)
Published 2019-01-29. Last modified 2026-06-17.