← Vulnerability feed

Vulnerability record · CVE-2006-4252 · published 14 November 2006

CVE-2006-4252: Powerdns recursor vulnerability

Powerdns · Recursor

PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.

5.0 CVSS 2.0 Medium EPSS 5.9% · top 7.0%
5.0CVSS 2.0 base score
5.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-4252 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4009Powerdns recursor memory buffer overflow vulnerabilityBuffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary…EPSS 18%9.8CVE-2019-3807Powerdns recursor insufficient verification of data authenticity vulnerabilityAn issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative…EPSS 0.35%8.8CVE-2020-10030Powerdns recursor out-of-bounds read vulnerabilityAn issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's ho…EPSS 24%8.2CVE-2025-59023Powerdns recursor authentication bypass by capture-replay vulnerabilityCrafted delegations or IP fragments can poison cached delegations in Recursor.EPSS 0.28%8.1CVE-2019-3806Powerdns recursor vulnerabilityAn issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP …EPSS 1.5%7.8CVE-2015-5470Powerdns authoritative vulnerabilityThe label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x…EPSS 11%7.8CVE-2015-1868PowerDNS label decompression self-referential name denial of serviceThe label decompression code in PowerDNS Recursor (3.5.x, 3.6.x before 3.6.3, 3.7.x before 3.7.2) and Authoritative Server (3.2.x, 3.3.x before 3.3.2…EPSS 82%analysed7.5CVE-2026-33256Powerdns recursor allocation without limits vulnerabilityAn attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2006-4252), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.