NIXPKGS-2026-0211
GitHub issue
published on 10 Feb 2026
Permalink
CVE-2026-0398
5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): LOW
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse removed package rotp
- @LeSuisse accepted
- @LeSuisse published on GitHub
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
Affected products
pdns-recursor
- <5.3.5
- <5.2.8
- <5.1.10
Package maintainers
-
@rnhmjoj Michele Guerini Rocco <rnhmjoj@inventati.org>