Description


An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.

Related CPE's


a

powerdns

authoritative

2

Weaknesses


134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-94

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

7.4 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-04-22T14:16:54.650Z

5 months ago

Last modified

2026-06-17T10:37:46.657Z

3 months ago