Vulnerability record · CVE-2015-1868 · published 18 May 2015
CVE-2015-1868: PowerDNS label decompression self-referential name denial of service
Powerdns · Authoritative
The label decompression code in PowerDNS Recursor (3.5.x, 3.6.x before 3.6.3, 3.7.x before 3.7.2) and Authoritative Server (3.2.x, 3.3.x before 3.3.2, 3.4.x before 3.4.4) mishandles a DNS name that refers to itself. A remote request containing such a name drives excessive CPU consumption or a crash, taking the resolver or authoritative service down.
Description
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.
AV:N/AC:L/Au:N/C:N/I:N/A:C
Automated analysis
high priorityUnauthenticated remote denial of service with a complete availability impact and very high EPSS, though no confirmed in-the-wild exploitation is recorded.
What it is
The label decompression code in PowerDNS Recursor (3.5.x, 3.6.x before 3.6.3, 3.7.x before 3.7.2) and Authoritative Server (3.2.x, 3.3.x before 3.3.2, 3.4.x before 3.4.4) mishandles a DNS name that refers to itself. A remote request containing such a name drives excessive CPU consumption or a crash, taking the resolver or authoritative service down.
Impact
An unauthenticated remote attacker can exhaust CPU or crash the PowerDNS process, causing denial of service for all clients relying on that resolver or authoritative server.
Attack surface
Reached over the network via DNS queries to the affected Recursor or Authoritative Server; no authentication or user interaction is required, as reflected by the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.817, 99.6th percentile), indicating strong predicted likelihood of exploitation activity.
What to do
- Upgrade PowerDNS Recursor to 3.6.3 or 3.7.2 (or later) and Authoritative Server to 3.3.2 or 3.4.4 (or later).
- Apply the vendor and distribution patches referenced in the Fedora and Debian advisories if immediate upgrade is not possible.
- Restrict DNS service exposure to trusted networks and rate-limit or filter queries where feasible.
- Monitor resolver and authoritative processes for abnormal CPU spikes and unexpected restarts.
Detection
- Alert on sustained high CPU or process restarts in PowerDNS Recursor or Authoritative Server.
- Inspect DNS query logs for names containing self-referential or malformed compression pointers.
- Correlate spikes in query volume from single sources with resolver degradation.
- Track PowerDNS crash or core dump events and review surrounding query patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-1868 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-1868), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.