← Vulnerability feed

Vulnerability record · CVE-2018-10851 · published 29 November 2018

CVE-2018-10851: Powerdns authoritative uncontrolled resource consumption vulnerability

Powerdns · Authoritative

PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.

7.5 CVSS 3.0 High EPSS 6.0% · top 6.9% CWE-400 · Uncontrolled resource consumptionCWE-772 · CWE-772
7.5CVSS 3.0 base score, v2 5.0
6.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed records that can lead to remote denial of service.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-10851 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4009Powerdns recursor memory buffer overflow vulnerabilityBuffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary…EPSS 18%9.8CVE-2026-33608Powerdns authoritative code injection vulnerabilityAn attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its confi…EPSS 0.59%9.8CVE-2020-24698Powerdns authoritative double free vulnerabilityAn issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might…EPSS 3.2%9.8CVE-2019-3807Powerdns recursor insufficient verification of data authenticity vulnerabilityAn issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative…EPSS 0.35%8.8CVE-2020-10030Powerdns recursor out-of-bounds read vulnerabilityAn issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's ho…EPSS 24%8.6CVE-2026-42000Powerdns authoritative command injection vulnerabilityInsufficient Validation of Names During AXFREPSS 0.54%8.2CVE-2025-59023Powerdns recursor authentication bypass by capture-replay vulnerabilityCrafted delegations or IP fragments can poison cached delegations in Recursor.EPSS 0.28%8.1CVE-2020-24696Powerdns authoritative race condition vulnerabilityAn issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can t…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2018-10851), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.