CVE-2025-59023
8.2PowerDNS · Recursor
Crafted delegations or IP fragments can lead to cache poisoning in PowerDNS Recursor, allowing unauthorized modification of cached records.
Executive summary
A critical vulnerability in PowerDNS Recursor allows unauthenticated remote attackers to perform cache poisoning via crafted delegations or IP fragments.
Vulnerability
The vulnerability stems from insufficient verification of data authenticity, where an unauthenticated attacker can supply crafted network traffic to poison the DNS cache.
Business impact
Successful exploitation of this vulnerability allows an attacker to redirect traffic by poisoning the DNS cache, potentially leading to man-in-the-middle attacks or the redirection of users to malicious infrastructure. Given the CVSS score of 8.2, this represents a significant risk to organizational integrity and data security, necessitating immediate attention to prevent unauthorized traffic redirection.
Remediation
Immediate Action: Upgrade PowerDNS Recursor to versions 5.3.1, 5.2.6, or 5.1.8 as applicable to your current branch.
Proactive Monitoring: Monitor network traffic for unusual DNS query patterns or unexpected responses that might indicate cache poisoning attempts.
Compensating Controls: Ensure that the Recursor is not exposed directly to the public internet and that appropriate access controls are in place to limit query sources.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability poses a high risk to DNS infrastructure by allowing attackers to compromise the integrity of resolution services. Organizations running affected versions of PowerDNS Recursor should prioritize the application of the vendor-provided patches immediately to prevent potential traffic interception and service manipulation.
Sources
Originally found and disclosed by Yuxiao Wu from Tsinghua University, Yunyi Zhang from Tsinghua University, Baojun Liu from Tsinghua University, Haixin Duan from Tsinghua University, Shiming Liu from Network and Information Security Lab, Tsinghua University, per the CVE Program record.