<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>PowerDNS Blog</title>
    <link>https://blog.powerdns.com</link>
    <description>The PowerDNS Blog has content on all the latest news, launches, products and solutions of PowerDNS.</description>
    <language>en</language>
    <pubDate>Mon, 08 Jun 2026 12:09:19 GMT</pubDate>
    <dc:date>2026-06-08T12:09:19Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>PowerDNS Authoritative Server 5.1.1 Released</title>
      <link>https://blog.powerdns.com/2026/06/08/powerdns-authoritative-server-5.1.1-released</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/06/08/powerdns-authoritative-server-5.1.1-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_Authoritative_release_blog.png" alt="PowerDNS Authoritative Server 5.1.1 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Despite our best efforts, a severe bug escaped our testing while working on the 5.1.0 release. Users of the LMDB backend, when not using the new ``lmdb-split-domain-table'', would fail to update their last notification timestamp, and cause secondary servers to keep trying to synchronize with their primary servers, and primary servers to keep asking their secondaries to do so.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/06/08/powerdns-authoritative-server-5.1.1-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_Authoritative_release_blog.png" alt="PowerDNS Authoritative Server 5.1.1 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Despite our best efforts, a severe bug escaped our testing while working on the 5.1.0 release. Users of the LMDB backend, when not using the new ``lmdb-split-domain-table'', would fail to update their last notification timestamp, and cause secondary servers to keep trying to synchronize with their primary servers, and primary servers to keep asking their secondaries to do so.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F06%2F08%2Fpowerdns-authoritative-server-5.1.1-released&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Latest Releases</category>
      <category>Authoritative Server</category>
      <pubDate>Mon, 08 Jun 2026 12:07:58 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/06/08/powerdns-authoritative-server-5.1.1-released</guid>
      <dc:date>2026-06-08T12:07:58Z</dc:date>
      <dc:creator>Peter van Dijk</dc:creator>
    </item>
    <item>
      <title>PowerDNS Authoritative Server 5.1.0 Released</title>
      <link>https://blog.powerdns.com/2026/06/03/powerdns-authoritative-server-5.1.0-released</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/06/03/powerdns-authoritative-server-5.1.0-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_Authoritative_release_blog.png" alt="PowerDNS Authoritative Server 5.1.0 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Being out of excuses to postpone this release, we are releasing PowerDNS Authoritative Server version 5.1.0 today.&lt;/p&gt; 
&lt;p&gt;A detailed list of changes can be found in the &lt;a href="https://doc.powerdns.com/authoritative/changelog/5.1.html#change-5.1.0"&gt;changelog&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;There are too many changes and bugfixes to mention in this short announcement; among the new features, you might be interested in structured logging or, for users of the LMDB backend, the ability to add comments to their RRsets, a feature which used to be available on SQL backends only.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/06/03/powerdns-authoritative-server-5.1.0-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_Authoritative_release_blog.png" alt="PowerDNS Authoritative Server 5.1.0 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Being out of excuses to postpone this release, we are releasing PowerDNS Authoritative Server version 5.1.0 today.&lt;/p&gt; 
&lt;p&gt;A detailed list of changes can be found in the &lt;a href="https://doc.powerdns.com/authoritative/changelog/5.1.html#change-5.1.0"&gt;changelog&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;There are too many changes and bugfixes to mention in this short announcement; among the new features, you might be interested in structured logging or, for users of the LMDB backend, the ability to add comments to their RRsets, a feature which used to be available on SQL backends only.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F06%2F03%2Fpowerdns-authoritative-server-5.1.0-released&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Authoritative Server</category>
      <pubDate>Wed, 03 Jun 2026 10:03:22 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/06/03/powerdns-authoritative-server-5.1.0-released</guid>
      <dc:date>2026-06-03T10:03:22Z</dc:date>
      <dc:creator>Peter van Dijk</dc:creator>
    </item>
    <item>
      <title>PowerDNS Recursor 5.2.10, 5.3.7 and 5.4.2 Released</title>
      <link>https://blog.powerdns.com/2026/06/03/powerdns-recursor-5.2.10-5.3.7-and-5.4.2-released</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/06/03/powerdns-recursor-5.2.10-5.3.7-and-5.4.2-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_recursor_release_blog.png" alt="PowerDNS Recursor 5.2.10, 5.3.7 and 5.4.2 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today we have released PowerDNS Recursor 5.2.10, 5.3.7 and 5.4.2.&lt;/p&gt; 
&lt;p&gt;These releases are maintenance releases that fix a few bugs and have a few improvements. The most important ones are: &lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/06/03/powerdns-recursor-5.2.10-5.3.7-and-5.4.2-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_recursor_release_blog.png" alt="PowerDNS Recursor 5.2.10, 5.3.7 and 5.4.2 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today we have released PowerDNS Recursor 5.2.10, 5.3.7 and 5.4.2.&lt;/p&gt; 
&lt;p&gt;These releases are maintenance releases that fix a few bugs and have a few improvements. The most important ones are: &lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F06%2F03%2Fpowerdns-recursor-5.2.10-5.3.7-and-5.4.2-released&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Latest Releases</category>
      <category>Recursor</category>
      <pubDate>Wed, 03 Jun 2026 08:19:20 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/06/03/powerdns-recursor-5.2.10-5.3.7-and-5.4.2-released</guid>
      <dc:date>2026-06-03T08:19:20Z</dc:date>
      <dc:creator>Otto Moerbeek</dc:creator>
    </item>
    <item>
      <title>PowerDNS DNSdist 2.1.0 Release Candidate 1 Released</title>
      <link>https://blog.powerdns.com/2026/06/02/powerdns-dnsdist-2.1.0-release-candidate-1-released</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/06/02/powerdns-dnsdist-2.1.0-release-candidate-1-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_dnsdist_release_blog.png" alt="PowerDNS DNSdist 2.1.0 Release Candidate 1 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today we released the first release candidate for PowerDNS DNSdist 2.1.0.&lt;br&gt;&lt;br&gt;This new version brings a lot of bug fixes since the second beta, including security issues that have been recently fixed in stable branches[&lt;a href="https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html"&gt;1&lt;/a&gt;][&lt;a href="https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-04.html"&gt;2&lt;/a&gt;]. We also tracked and fixed a performance regression, making the performance of this release candidate better than previous releases, especially for cache hits.&lt;br&gt;&lt;br&gt;Compared to 2.0, 2.1 also brings the following new features:&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/06/02/powerdns-dnsdist-2.1.0-release-candidate-1-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_dnsdist_release_blog.png" alt="PowerDNS DNSdist 2.1.0 Release Candidate 1 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today we released the first release candidate for PowerDNS DNSdist 2.1.0.&lt;br&gt;&lt;br&gt;This new version brings a lot of bug fixes since the second beta, including security issues that have been recently fixed in stable branches[&lt;a href="https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html"&gt;1&lt;/a&gt;][&lt;a href="https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-04.html"&gt;2&lt;/a&gt;]. We also tracked and fixed a performance regression, making the performance of this release candidate better than previous releases, especially for cache hits.&lt;br&gt;&lt;br&gt;Compared to 2.0, 2.1 also brings the following new features:&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F06%2F02%2Fpowerdns-dnsdist-2.1.0-release-candidate-1-released&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>DNSdist</category>
      <pubDate>Tue, 02 Jun 2026 10:15:17 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/06/02/powerdns-dnsdist-2.1.0-release-candidate-1-released</guid>
      <dc:date>2026-06-02T10:15:17Z</dc:date>
      <dc:creator>Remi Gacogne</dc:creator>
    </item>
    <item>
      <title>PowerDNS DNSdist 2.0.6 Released</title>
      <link>https://blog.powerdns.com/2026/05/21/powerdns-dnsdist-2.0.6-released</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/05/21/powerdns-dnsdist-2.0.6-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_dnsdist_release_blog.png" alt="PowerDNS DNSdist 2.0.6 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today we released DNSdist 2.0.6, fixing several issues. The notable ones are:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;the feature that was introduced in 2.0.0 to limit the rate of new TCP or QUIC connections that a given client can open per second has a serious bug, coming from a confusion over the interval, which is set in minutes, and the rate, which is set in seconds, causing clients to be blocked a lot sooner than they should have been&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;there was a data race in the CDB Key-Value store implementation. This was fixed by preventing threads from accessing the same CDB object concurrently, which might have a performance impact for users that rely heavily on CDB. Please reach out to us if you experience such a performance impact&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;the BPFFilter::addRangeRule feature was not working properly&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;configured buffer sizes for UDP sockets were only applied to incoming sockets, not outgoing ones&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;AF_XDP/XSK could not be enabled from YAML&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;the TLS session cache for outgoing connections to backends was not properly cleaned up&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;the computation of the "Top N" metrics for suffix-based dynamic block counters was wrong&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;DownstreamState::setHealthCheckParams was sometimes overwriting the wrong value&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;a memory leak was found in the SNMP metrics implementation&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;the maximum size of a DNS over QUIC query was slightly off, which might have been a problem for very large queries&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/05/21/powerdns-dnsdist-2.0.6-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_dnsdist_release_blog.png" alt="PowerDNS DNSdist 2.0.6 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today we released DNSdist 2.0.6, fixing several issues. The notable ones are:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;the feature that was introduced in 2.0.0 to limit the rate of new TCP or QUIC connections that a given client can open per second has a serious bug, coming from a confusion over the interval, which is set in minutes, and the rate, which is set in seconds, causing clients to be blocked a lot sooner than they should have been&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;there was a data race in the CDB Key-Value store implementation. This was fixed by preventing threads from accessing the same CDB object concurrently, which might have a performance impact for users that rely heavily on CDB. Please reach out to us if you experience such a performance impact&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;the BPFFilter::addRangeRule feature was not working properly&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;configured buffer sizes for UDP sockets were only applied to incoming sockets, not outgoing ones&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;AF_XDP/XSK could not be enabled from YAML&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;the TLS session cache for outgoing connections to backends was not properly cleaned up&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;the computation of the "Top N" metrics for suffix-based dynamic block counters was wrong&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;DownstreamState::setHealthCheckParams was sometimes overwriting the wrong value&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;a memory leak was found in the SNMP metrics implementation&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;the maximum size of a DNS over QUIC query was slightly off, which might have been a problem for very large queries&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F05%2F21%2Fpowerdns-dnsdist-2.0.6-released&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Latest Releases</category>
      <category>DNSdist</category>
      <pubDate>Thu, 21 May 2026 11:41:22 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/05/21/powerdns-dnsdist-2.0.6-released</guid>
      <dc:date>2026-05-21T11:41:22Z</dc:date>
      <dc:creator>Remi Gacogne</dc:creator>
    </item>
    <item>
      <title>PowerDNS Security Advisory 2026-06 for PowerDNS Authoritative Server</title>
      <link>https://blog.powerdns.com/2026/05/20/powerdns-security-advisory-2026-06-for-powerdns-authoritative-server</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/05/20/powerdns-security-advisory-2026-06-for-powerdns-authoritative-server" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_Authoritative_release_blog.png" alt="PowerDNS Security Advisory 2026-06 for PowerDNS Authoritative Server" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today, we are releasing two new versions of the PowerDNS Authoritative Server.&lt;/p&gt; 
&lt;p&gt;These 4.9.15&amp;nbsp;and 5.0.5&amp;nbsp;versions provide fixes for the following PowerDNS Security Advisory: &lt;a href="https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html"&gt;PowerDNS Security Advisory 2026-06: Multiple Issues&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;The security issues being fixed with these releases are low or medium-severity, and most of them involve specific back-ends and/or configurations. They are:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;CVE-2026-41999 (only concerns 5.0.x)&lt;br&gt;When using views, queries sent using TCP Proxy Protocol will select the view according to the address of the proxy, rather than the address of the initial query. This can lead to wrong data being returned.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt;CVE-2026-42000&lt;br&gt;Missing escaping of special characters (such as $ or @) in DNS names received during an AXFR operation can lead to an incorrect (non-parseable) Bind backend configuration to be written, causing this backend to fail until manual operation is performed to fix the configuration.&lt;/li&gt; 
 &lt;li&gt;CVE-2026-42001&lt;br&gt;Missing sanity checks of the answer to the initial SOA query, when running in auto-secondary mode and receiving a notification for an not-yet-known domain may cause the server to crash.&lt;/li&gt; 
 &lt;li&gt;CVE-2026-42002&lt;br&gt;Multiple concurrency and locking defects in the GSS-TSIG code can lead to memory corruption due to accidental data structure sharing, which can in turn lead to a program crash.&lt;br&gt;Moreover, the lack of bounds on the number of in-flight GSS-TSIG contexts can lead to unbounded memory consumption in case of an excessive number of requests at a given time. A limit of 1000 contexts is now enforced, and can be modified with the "gss-max-contexts" parameter in server configuration.&lt;/li&gt; 
 &lt;li&gt;CVE-2026-42396&lt;br&gt;Missing proper escaping of double-quote characters when computing labels will cause AXFR of a catalog zone with a member whose producer group option contains such a character to fail.&lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/05/20/powerdns-security-advisory-2026-06-for-powerdns-authoritative-server" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_Authoritative_release_blog.png" alt="PowerDNS Security Advisory 2026-06 for PowerDNS Authoritative Server" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today, we are releasing two new versions of the PowerDNS Authoritative Server.&lt;/p&gt; 
&lt;p&gt;These 4.9.15&amp;nbsp;and 5.0.5&amp;nbsp;versions provide fixes for the following PowerDNS Security Advisory: &lt;a href="https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html"&gt;PowerDNS Security Advisory 2026-06: Multiple Issues&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;The security issues being fixed with these releases are low or medium-severity, and most of them involve specific back-ends and/or configurations. They are:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;CVE-2026-41999 (only concerns 5.0.x)&lt;br&gt;When using views, queries sent using TCP Proxy Protocol will select the view according to the address of the proxy, rather than the address of the initial query. This can lead to wrong data being returned.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt;CVE-2026-42000&lt;br&gt;Missing escaping of special characters (such as $ or @) in DNS names received during an AXFR operation can lead to an incorrect (non-parseable) Bind backend configuration to be written, causing this backend to fail until manual operation is performed to fix the configuration.&lt;/li&gt; 
 &lt;li&gt;CVE-2026-42001&lt;br&gt;Missing sanity checks of the answer to the initial SOA query, when running in auto-secondary mode and receiving a notification for an not-yet-known domain may cause the server to crash.&lt;/li&gt; 
 &lt;li&gt;CVE-2026-42002&lt;br&gt;Multiple concurrency and locking defects in the GSS-TSIG code can lead to memory corruption due to accidental data structure sharing, which can in turn lead to a program crash.&lt;br&gt;Moreover, the lack of bounds on the number of in-flight GSS-TSIG contexts can lead to unbounded memory consumption in case of an excessive number of requests at a given time. A limit of 1000 contexts is now enforced, and can be modified with the "gss-max-contexts" parameter in server configuration.&lt;/li&gt; 
 &lt;li&gt;CVE-2026-42396&lt;br&gt;Missing proper escaping of double-quote characters when computing labels will cause AXFR of a catalog zone with a member whose producer group option contains such a character to fail.&lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F05%2F20%2Fpowerdns-security-advisory-2026-06-for-powerdns-authoritative-server&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Authoritative Server</category>
      <pubDate>Wed, 20 May 2026 13:02:52 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/05/20/powerdns-security-advisory-2026-06-for-powerdns-authoritative-server</guid>
      <dc:date>2026-05-20T13:02:52Z</dc:date>
      <dc:creator>Peter van Dijk</dc:creator>
    </item>
    <item>
      <title>Automatic authenticated DNSSEC Bootstrapping in PowerDNS Authoritative</title>
      <link>https://blog.powerdns.com/2026/05/12/automatic-authenticated-dnssec-bootstrapping-in-powerdns-authoritative-server</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/05/12/automatic-authenticated-dnssec-bootstrapping-in-powerdns-authoritative-server" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/bootstrap.png" alt="Automatic authenticated DNSSEC Bootstrapping in PowerDNS Authoritative" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h4&gt;&lt;span&gt;&lt;strong&gt;The chain of trust is better off without leaps of faith: Automatic authenticated DNSSEC Bootstrapping in PowerDNS Authoritative Server&lt;/strong&gt;&lt;/span&gt;&lt;/h4&gt; 
&lt;p&gt;Authors: Barbara Jantzen &amp;amp; Peter Thomassen (both from deSEC)&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/05/12/automatic-authenticated-dnssec-bootstrapping-in-powerdns-authoritative-server" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/bootstrap.png" alt="Automatic authenticated DNSSEC Bootstrapping in PowerDNS Authoritative" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h4&gt;&lt;span&gt;&lt;strong&gt;The chain of trust is better off without leaps of faith: Automatic authenticated DNSSEC Bootstrapping in PowerDNS Authoritative Server&lt;/strong&gt;&lt;/span&gt;&lt;/h4&gt; 
&lt;p&gt;Authors: Barbara Jantzen &amp;amp; Peter Thomassen (both from deSEC)&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F05%2F12%2Fautomatic-authenticated-dnssec-bootstrapping-in-powerdns-authoritative-server&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Guest post</category>
      <pubDate>Tue, 12 May 2026 12:16:52 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/05/12/automatic-authenticated-dnssec-bootstrapping-in-powerdns-authoritative-server</guid>
      <dc:date>2026-05-12T12:16:52Z</dc:date>
      <dc:creator>Peter van Dijk</dc:creator>
    </item>
    <item>
      <title>PowerDNS Authoritative Server 5.1.0-beta1 Released</title>
      <link>https://blog.powerdns.com/2026/05/07/powerdns-authoritative-server-5.1.0-beta1-released</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/05/07/powerdns-authoritative-server-5.1.0-beta1-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_Authoritative_release_blog.png" alt="PowerDNS Authoritative Server 5.1.0-beta1 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;On this lovely day, we are releasing version 5.1.0-beta1 of the PowerDNS Authoritative Server. It contains many small new features and improvements over the previous 5.1.0-alpha1 release, as well as the unavoidable bug fixes.&lt;br&gt;&lt;br&gt;You might be especially interested in structured logging or, for users of the LMDB backend, the ability to add comments to their RRsets, a feature which used to be available on SQL backends only.&lt;/p&gt; 
&lt;p&gt;Please test it and help us make the final 5.1.0 release a success!&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/05/07/powerdns-authoritative-server-5.1.0-beta1-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_Authoritative_release_blog.png" alt="PowerDNS Authoritative Server 5.1.0-beta1 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;On this lovely day, we are releasing version 5.1.0-beta1 of the PowerDNS Authoritative Server. It contains many small new features and improvements over the previous 5.1.0-alpha1 release, as well as the unavoidable bug fixes.&lt;br&gt;&lt;br&gt;You might be especially interested in structured logging or, for users of the LMDB backend, the ability to add comments to their RRsets, a feature which used to be available on SQL backends only.&lt;/p&gt; 
&lt;p&gt;Please test it and help us make the final 5.1.0 release a success!&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F05%2F07%2Fpowerdns-authoritative-server-5.1.0-beta1-released&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Authoritative Server</category>
      <pubDate>Thu, 07 May 2026 14:35:36 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/05/07/powerdns-authoritative-server-5.1.0-beta1-released</guid>
      <dc:date>2026-05-07T14:35:36Z</dc:date>
      <dc:creator>Peter van Dijk</dc:creator>
    </item>
    <item>
      <title>Introducing PowerDNS Authoritative Essentials</title>
      <link>https://blog.powerdns.com/introducing-powerdns-authoritative-essentials</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/introducing-powerdns-authoritative-essentials" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS/images/PowerDNS%20Authoritative%20Essentials%20-%20Package%20overview.png" alt="Introducing PowerDNS Authoritative Essentials" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span&gt;We’re thrilled to announce the launch of &lt;a&gt;&lt;/a&gt;&lt;strong&gt;&lt;a href="https://inc.powerdns.com/authoritative-essentials"&gt;PowerDNS Authoritative Essentials&lt;/a&gt;&lt;/strong&gt; – a streamlined, enterprise-grade solution designed for organizations that require high-performance, secure, and dependable DNS for their domain portfolios.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/introducing-powerdns-authoritative-essentials" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS/images/PowerDNS%20Authoritative%20Essentials%20-%20Package%20overview.png" alt="Introducing PowerDNS Authoritative Essentials" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span&gt;We’re thrilled to announce the launch of &lt;a&gt;&lt;/a&gt;&lt;strong&gt;&lt;a href="https://inc.powerdns.com/authoritative-essentials"&gt;PowerDNS Authoritative Essentials&lt;/a&gt;&lt;/strong&gt; – a streamlined, enterprise-grade solution designed for organizations that require high-performance, secure, and dependable DNS for their domain portfolios.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2Fintroducing-powerdns-authoritative-essentials&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Authoritative Server</category>
      <pubDate>Tue, 05 May 2026 09:49:35 GMT</pubDate>
      <guid>https://blog.powerdns.com/introducing-powerdns-authoritative-essentials</guid>
      <dc:date>2026-05-05T09:49:35Z</dc:date>
      <dc:creator>Oliver Michler</dc:creator>
    </item>
    <item>
      <title>PowerDNS DNSdist 1.9.14 and 2.0.5 Released</title>
      <link>https://blog.powerdns.com/2026/04/23/powerdns-dnsdist-1.9.14-and-2.0.5-released</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/04/23/powerdns-dnsdist-1.9.14-and-2.0.5-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_dnsdist_release_blog.png" alt="PowerDNS DNSdist 1.9.14 and 2.0.5 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today we again released two new versions of DNSdist, 1.9.14 and 2.0.5, fixing one regression introduced in 1.9.13 and 2.0.4, and several small issues that were not included in yesterday's security releases.&lt;br&gt;&lt;br&gt;The regression introduced in 1.9.13 and 2.0.4 concerns the PRSD detection mechanism enabled with DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI, and causes an exception to be raised when accessing StatNode::fullname from the Lua visitor function.&lt;br&gt;&lt;br&gt;The other issues fixed in this release are:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;(1.9.14 and 2.0.5) When DNSdist is compiled in "single acceptor thread" mode, which is designed for embedded systems with low memory, a TCP worker thread was not always created by default, even when DOQ and DoH3 support was enabled, leading to a crash.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;(2.0.5) The buffers allocated for recvmmsg might have been too large, wasting memory&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;(2.0.5) When the trustForwardForHeader option is used, and the upstream proxy did include X-Forwarded-For header for at least one query in an established connection but somehow does not include it for a subsequent query, DNSdist should reset the client address to the address of the proxy instead of using the last received one&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;(2.0.5): Fix handling of long HTTP/2 Date headers if the administrator explictly used a non-POSIX locale&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;(2.0.5): Detection of some TLS functions was missing when compiling with meson: TLS_client_method and gnutls_transport_set_fastopen&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://blog.powerdns.com/2026/04/23/powerdns-dnsdist-1.9.14-and-2.0.5-released" title="" class="hs-featured-image-link"&gt; &lt;img src="https://blog.powerdns.com/hubfs/PowerDNS_dnsdist_release_blog.png" alt="PowerDNS DNSdist 1.9.14 and 2.0.5 Released" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Today we again released two new versions of DNSdist, 1.9.14 and 2.0.5, fixing one regression introduced in 1.9.13 and 2.0.4, and several small issues that were not included in yesterday's security releases.&lt;br&gt;&lt;br&gt;The regression introduced in 1.9.13 and 2.0.4 concerns the PRSD detection mechanism enabled with DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI, and causes an exception to be raised when accessing StatNode::fullname from the Lua visitor function.&lt;br&gt;&lt;br&gt;The other issues fixed in this release are:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;(1.9.14 and 2.0.5) When DNSdist is compiled in "single acceptor thread" mode, which is designed for embedded systems with low memory, a TCP worker thread was not always created by default, even when DOQ and DoH3 support was enabled, leading to a crash.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;(2.0.5) The buffers allocated for recvmmsg might have been too large, wasting memory&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;(2.0.5) When the trustForwardForHeader option is used, and the upstream proxy did include X-Forwarded-For header for at least one query in an established connection but somehow does not include it for a subsequent query, DNSdist should reset the client address to the address of the proxy instead of using the last received one&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;(2.0.5): Fix handling of long HTTP/2 Date headers if the administrator explictly used a non-POSIX locale&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;(2.0.5): Detection of some TLS functions was missing when compiling with meson: TLS_client_method and gnutls_transport_set_fastopen&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=20334960&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fblog.powerdns.com%2F2026%2F04%2F23%2Fpowerdns-dnsdist-1.9.14-and-2.0.5-released&amp;amp;bu=https%253A%252F%252Fblog.powerdns.com&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>DNSdist</category>
      <pubDate>Thu, 23 Apr 2026 09:45:49 GMT</pubDate>
      <guid>https://blog.powerdns.com/2026/04/23/powerdns-dnsdist-1.9.14-and-2.0.5-released</guid>
      <dc:date>2026-04-23T09:45:49Z</dc:date>
      <dc:creator>Remi Gacogne</dc:creator>
    </item>
  </channel>
</rss>
