CVE-2026-52686: Powerdns Recursor

Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.

Affected products

  • Powerdns Recursor: from 5.2.0, before 5.2.12 (fixed in 5.2.12); from 5.3.0, before 5.3.9 (fixed in 5.3.9); from 5.4.0, before 5.4.4 (fixed in 5.4.4)

Published 2026-07-23. Last modified 2026-07-23.