An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can trigger a race condition leading to a crash, or possibly arbitrary code execution, by sending crafted queries with a GSS-TSIG signature.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HPowerdns Authoritative
APPPowerdns≤ 4.3.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEAuth BypassRace Condition
CWE
Related vulnerabilities
CVE-2020-24698CRITICAL9.8PL ✓same product
PowerDNS Authoritative: double-free via GSS-TSIG umożliwia RCE
CVE-2026-42001HIGH7.5same product
Insufficient Validation of Autoprimary SOA Queries
CVE-2026-33608HIGH7.4same product
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but ...
CVE-2020-24697HIGH7.5same product
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A...
CVE-2015-5230HIGH7.5same product
The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows r...