Today we have released PowerDNS Authoritative Server 4.9.17, 5.0.7, 5.1.4, Recursor 5.2.13, 5.3.10, 5.4.5, and dnsdist 1.9.16, 2.0.8, 2.1.1.
These releases provide fixes for PowerDNS Security Advisory
- 2026-11 for PowerDNS Authoritative Server, Recursor and dnsdist: A crafted DNS packet can cause increased memory and CPU consumption
The CVE associated with this advisory is of severity High:
- CVE-2026-52682: A crafted DNS packet can cause increased memory and CPU consumption
Please refer to the changelogs for Authoritative Server (4.9.17, 5.0.7, 5.1.4), Recursor (5.2.13, 5.3.10 and 5.4.5) and dnsdist (1.9.16, 2.0.8, 2.1.1) and the full security advisory for additional details.
Please send us all feedback and issues you might have via the mailing list, or in case of a bug, via GitHub.
The tarballs for Authoritative Server (4.9.17, 5.0.7, 5.1.4 with signature files 4.9.17, 5.0.7, 5.1.4), Recursor (5.2.13, 5.3.10, 5.4.5 with signature files 5.2.13, 5.3.10, 5.4.5) and dnsdist (1.9.16, 2.0.8, 2.1.1 with signature files 1.9.16, 2.0.8, 2.1.1) are available from our download server and packages for several distributions are available from our repository.
Recently we made changes to our Open Source End of Life policy. Older release trains are now supported for one year after the following major release. Consult the EOL policy for more details.
We are grateful to the PowerDNS community for the reporting of bugs, issues, feature requests, and especially to the submitters of fixes and implementations of features.
