Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-52690

Spoofed answers can mark an authoritative non-EDNS capable_CVE-2026-52690

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by tha...

PowerDNS Recursor 5.2.0 CVE
MEDIUM 6.7 CVE-2026-46732

CVE-2026-46732_CVE-2026-46732

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchroni...

Dell Display and Peripheral Manager CVE
MEDIUM 5.3 CVE-2026-42390

ZONEMD validation can be bypassed_CVE-2026-42390

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

PowerDNS Recursor 5.4.0 CVE
MEDIUM 5.3 CVE-2026-42389

Reject more queries with invalid header values_CVE-2026-42389

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

PowerDNS Recursor 5.4.0 CVE
MEDIUM 5.9 CVE-2026-42388

Missing input validation for catalog zones_CVE-2026-42388

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

PowerDNS Recursor 5.2.0 CVE
MEDIUM 5.9 CVE-2026-42387

Insufficient input validation in ZoneToCache_CVE-2026-42387

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient inpu...

PowerDNS Recursor 5.2.0 CVE
MEDIUM 5.3 CVE-2026-40012

Information about ECS zero scoped answers might leak to clients that use a specific ECS_CVE-2026-40012

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

PowerDNS Recursor 5.2.0 CVE
MEDIUM 5.3 CVE-2026-6432

Improper bounds validation in EmberZNet SDK_CVE-2026-6432

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

Silicon Labs SiSDK CVE
MEDIUM 5.3 CVE-2026-57587

SQL Injection in Nessus via Reverse DNS Lookup_CVE-2026-57587

A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject mal...

tenable Nessus CVE
MEDIUM 6.3 CVE-2026-57536

Insufficient validation of payment status in pretix-mollie_CVE-2026-57536

Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status respons...

pretix pretix-mollie CVE