CVE-2026-52690: Powerdns Recursor

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.

Affected products

  • Powerdns Recursor: from 5.2.0, before 5.2.11 (fixed in 5.2.11); from 5.3.0, before 5.3.8 (fixed in 5.3.8); from 5.4.0, before 5.4.3 (fixed in 5.4.3)

Published 2026-06-25. Last modified 2026-06-25.