Get real-time updates on Telegram
CVE-2025-59029: recursor 5.3.0, 5.3.1; +1 more affected products
CVE-2025-59029. CVSS 3.1 base score 5.3 (MEDIUM, Vendor/CNA). EPSS 0.00374 (percentile 0.2918), scored 2026-10-06.
Affected technology
recursor · 5.3.0
powerdns
recursor · 5.3.1
powerdns
Recursor · 5.3.0 to before 5.3.2
PowerDNS
Component: Record cache
File: recursor_cache.cc
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY. Vendor/CNA’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality and integrity impact as none; availability impact as low.
- CWE
- CWE-617
- CCR priority
- 21.3 /100 (P4)
- CVSS 3.1
- 5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L · Vendor/CNA
- EPSS
- 0.00374 · percentile 0.2918 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-59029.html