CVE-2026-52686: Powerdns Recursor
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
Affected products
- Powerdns Recursor: from 5.2.0, before 5.2.12 (fixed in 5.2.12); from 5.3.0, before 5.3.9 (fixed in 5.3.9); from 5.4.0, before 5.4.4 (fixed in 5.4.4)
Published 2026-07-23. Last modified 2026-07-23.