← Vulnerability feed

Vulnerability record · CVE-2021-36754 · published 30 July 2021

CVE-2021-36754: PowerDNS Authoritative Server crash via QTYPE 65535 query

Powerdns · Authoritative Server

PowerDNS Authoritative Server 4.5.0 before 4.5.1 crashes when it receives a query with QTYPE 65535, which triggers an out-of-bounds exception. The flaw is a remotely reachable denial of service in a core DNS component, so any exposed authoritative server running the affected version is at risk of going down.

7.5 CVSS 3.1 High EPSS 65% · top 0.8% CWE-119 · Memory buffer overflow
7.5CVSS 3.1 base score, v2 5.0
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE 65535) that causes an out-of-bounds exception.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote unauthenticated crash of a DNS server with a high EPSS score and no listed KEV entry, making it a serious availability risk for exposed instances.

What it is

PowerDNS Authoritative Server 4.5.0 before 4.5.1 crashes when it receives a query with QTYPE 65535, which triggers an out-of-bounds exception. The flaw is a remotely reachable denial of service in a core DNS component, so any exposed authoritative server running the affected version is at risk of going down.

Impact

An unauthenticated attacker can crash the PowerDNS process, causing loss of DNS resolution for zones served by that instance until it is restarted. No data confidentiality or integrity impact is described; the effect is availability only.

Attack surface

The vulnerability is reached over the network by sending a crafted DNS query with QTYPE 65535 to the authoritative server. No authentication or user interaction is required, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

The record does not state that exploitation has been observed; CISA KEV does not list it, while EPSS is high at 0.64857 (99.2nd percentile), indicating elevated predicted likelihood. References are vendor advisories and a mailing list post, with no public exploit tag.

What to do

  • Upgrade PowerDNS Authoritative Server to 4.5.1 or later, which the vendor advisory identifies as the fixed release.
  • If immediate upgrade is not possible, restrict DNS query access to trusted resolvers and networks rather than exposing the server broadly.
  • Monitor the PowerDNS process for unexpected restarts or crashes and alert on them.
  • Review exposure of authoritative servers on the public internet and remove unnecessary reachability.

Detection

  • Alert on PowerDNS process termination or restart events correlated with inbound DNS traffic.
  • Search DNS query logs for QTYPE 65535 requests, which are abnormal for normal resolution traffic.
  • Baseline and monitor for spikes in malformed or unusual QTYPE queries against authoritative servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-36754 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-3871Powerdns authoritative server improper input validation vulnerabilityA vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user whe…EPSS 13%7.5CVE-2022-27227Powerdns authoritative server vulnerabilityIn PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and…EPSS 5.0%6.8CVE-2016-6172Opensuse leap uncontrolled resource consumption vulnerabilityPowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary…EPSS 3.8%6.4CVE-2008-3337Powerdns authoritative server improper input validation vulnerabilityPowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other …EPSS 6.1%5.0CVE-2012-0206Powerdns authoritative server vulnerabilitycommon_startup.cc in PowerDNS (aka pdns) Authoritative Server before 2.9.22.5 and 3.x before 3.0.1 allows remote attackers to cause a denial of servi…EPSS 5.3%4.3CVE-2019-10203Powerdns authoritative server vulnerabilityPowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a serial between 2^31 and 2^32-1 whi…EPSS 1.6%9.5CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2021-36754), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.