Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0012

NIXPKGS-2026-0012
published on 13 Jan 2026
updated 4 weeks, 1 day ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Insufficient validation of incoming notifies over TCP can lead to a denial of service in Recursor

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

Affected products

pdns-recursor
  • <5.1.9
  • <5.2.7
  • <5.3.3

Matching in nixpkgs

Package maintainers

Upstream advisory: https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-08.html