CVE-2026-52688: Powerdns Recursor
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Affected products
- Powerdns Recursor: from 5.2.0, before 5.2.12 (fixed in 5.2.12); from 5.3.0, before 5.3.9 (fixed in 5.3.9); from 5.4.0, before 5.4.4 (fixed in 5.4.4)
Published 2026-07-23. Last modified 2026-07-23.