CVE-2025-59023

8.2

PowerDNS · Recursor

Crafted delegations or IP fragments can lead to cache poisoning in PowerDNS Recursor, allowing unauthorized modification of cached records.

Executive summary

A critical vulnerability in PowerDNS Recursor allows unauthenticated remote attackers to perform cache poisoning via crafted delegations or IP fragments.

Vulnerability

The vulnerability stems from insufficient verification of data authenticity, where an unauthenticated attacker can supply crafted network traffic to poison the DNS cache.

Business impact

Successful exploitation of this vulnerability allows an attacker to redirect traffic by poisoning the DNS cache, potentially leading to man-in-the-middle attacks or the redirection of users to malicious infrastructure. Given the CVSS score of 8.2, this represents a significant risk to organizational integrity and data security, necessitating immediate attention to prevent unauthorized traffic redirection.

Remediation

Immediate Action: Upgrade PowerDNS Recursor to versions 5.3.1, 5.2.6, or 5.1.8 as applicable to your current branch.

Proactive Monitoring: Monitor network traffic for unusual DNS query patterns or unexpected responses that might indicate cache poisoning attempts.

Compensating Controls: Ensure that the Recursor is not exposed directly to the public internet and that appropriate access controls are in place to limit query sources.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability poses a high risk to DNS infrastructure by allowing attackers to compromise the integrity of resolution services. Organizations running affected versions of PowerDNS Recursor should prioritize the application of the vendor-provided patches immediately to prevent potential traffic interception and service manipulation.

Sources

Originally found and disclosed by Yuxiao Wu from Tsinghua University, Yunyi Zhang from Tsinghua University, Baojun Liu from Tsinghua University, Haixin Duan from Tsinghua University, Shiming Liu from Network and Information Security Lab, Tsinghua University, per the CVE Program record.