CVE-2025-59029

Source
https://cve.org/CVERecord?id=CVE-2025-59029
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59029.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-59029
Downstream
Published
2025-12-09T09:16:03Z
Modified
2026-08-12T03:51:40Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Internal logic flaw in cache management can lead to a denial of service in PowerDNS Recursor
Details

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

Database specific
{
    "cna_assigner": "OX",
    "cwe_ids": [
        "CWE-617"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59029.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.3.0"
                },
                {
                    "fixed": "5.3.2"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/powerdns/pdns

Affected ranges

Type
GIT
Repo
https://github.com/powerdns/pdns
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:powerdns:recursor:5.3.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:powerdns:recursor:5.3.1:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "5.3.0-NA"
        },
        {
            "last_affected": "5.3.0-NA"
        },
        {
            "introduced": "5.3.1"
        },
        {
            "last_affected": "5.3.1"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

5.*
5.3.0-NA
5.3.1
rec-5.*
rec-5.3.0
rec-5.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59029.json"