← Vulnerability feed

Vulnerability record · CVE-2018-16855 · published 3 December 2018

CVE-2018-16855: PowerDNS Recursor out-of-bounds read in query hash crashes resolver

Powerdns · Recursor

PowerDNS Recursor before 4.1.8 performs an out-of-bounds memory read while hashing a DNS query for packet cache lookup. A remote attacker can trigger it with a crafted query, and the read can crash the recursor. Because the recursor is the component that answers client DNS queries, a crash takes name resolution down for everything relying on it.

7.5 CVSS 3.0 High EPSS 59% · top 0.9% CWE-125 · Out-of-bounds read
7.5CVSS 3.0 base score, v2 5.0
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory read while computing the hash of the query for a packet cache lookup, possibly leading to a crash.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated denial of service against a core DNS service with a high EPSS score, though no confirmed in-the-wild exploitation is recorded.

What it is

PowerDNS Recursor before 4.1.8 performs an out-of-bounds memory read while hashing a DNS query for packet cache lookup. A remote attacker can trigger it with a crafted query, and the read can crash the recursor. Because the recursor is the component that answers client DNS queries, a crash takes name resolution down for everything relying on it.

Impact

An attacker gains denial of service: the recursor process can crash, interrupting DNS resolution for all clients using it. The flaw is an out-of-bounds read, so no data disclosure or code execution is described in the record.

Attack surface

Reachable over the network by sending a DNS query to the recursor; the CVSS vector shows no privileges and no user interaction required. No authentication is needed, so any host that can reach the recursor's DNS port can attempt it.

Exploitation

Not listed in CISA KEV and no public exploit or exploitation tag appears in the references, but EPSS is high (0.59469, 99th percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Upgrade PowerDNS Recursor to 4.1.8 or later, per the vendor advisory.
  • If immediate upgrade is not possible, restrict DNS service access to trusted client networks and block recursion from untrusted sources.
  • Run the recursor under a supervisor or systemd with automatic restart to limit outage duration from a crash.
  • Monitor the vendor advisory and distribution packages for backported fixes and apply them.
  • Reduce exposure by placing recursors behind ACLs or rate limiting so arbitrary internet hosts cannot send queries directly.

Detection

  • Alert on recursor process crashes, core dumps, or unexpected restarts in systemd/journal or crash logs.
  • Monitor for sudden drops or gaps in DNS query/response volume from a recursor instance.
  • Watch for bursts of malformed or unusual DNS queries directed at recursor hosts from single sources.
  • Track recursor version inventory to find instances still below 4.1.8.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-16855 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4009Powerdns recursor memory buffer overflow vulnerabilityBuffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary…EPSS 18%9.8CVE-2019-3807Powerdns recursor insufficient verification of data authenticity vulnerabilityAn issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative…EPSS 0.35%8.8CVE-2020-10030Powerdns recursor out-of-bounds read vulnerabilityAn issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's ho…EPSS 24%8.2CVE-2025-59023Powerdns recursor authentication bypass by capture-replay vulnerabilityCrafted delegations or IP fragments can poison cached delegations in Recursor.EPSS 0.28%8.1CVE-2019-3806Powerdns recursor vulnerabilityAn issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP …EPSS 1.5%7.8CVE-2015-5470Powerdns authoritative vulnerabilityThe label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x…EPSS 11%7.8CVE-2015-1868PowerDNS label decompression self-referential name denial of serviceThe label decompression code in PowerDNS Recursor (3.5.x, 3.6.x before 3.6.3, 3.7.x before 3.7.2) and Authoritative Server (3.2.x, 3.3.x before 3.3.2…EPSS 82%analysed7.5CVE-2026-33256Powerdns recursor allocation without limits vulnerabilityAn attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…EPSS 0.80%

Source: NIST National Vulnerability Database (record CVE-2018-16855), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.