CVE-2026-52686
EUVD-2026-4793123.07.2026, 09:16
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| powerdns | recursor | 5.2.0 ≤ 𝑥 < 5.2.12 | CNA |
| powerdns | recursor | 5.3.0 ≤ 𝑥 < 5.3.9 | CNA |
| powerdns | recursor | 5.4.0 ≤ 𝑥 < 5.4.4 | CNA |
Debian Releases
Common Weakness Enumeration