CVE-2025-59023Disclosure(powerdns / recursor)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch powerdns recursor systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crafted delegations or IP fragments can poison cached delegations in Recursor.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-294

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • recursor

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-16); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
recursor

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-09: 2Mentions · 2026-02-16: 3Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-02-09: 2Technical Details · 2026-02-16: 3Technical Details · 2026-04-28: 102-0902-1604-28
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Patch
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-092
Disclosure2
2026-02-163
Disclosure1General2
2026-04-281
Patch1
Full discourse6 posts
  • Yasuhiro Morishita@OrangeMorishita
    General

    【自分用メモ】2025年10月に公開されたキャッシュポイズニング脆弱性の論文が出た。まだ読んでいない。 CVE-2025-40778(BIND)、CVE-2025-11411(Unbound)、CVE-2025-59023(PowerDNS Recursor) Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick Checking - NDSS Symposium https://www.ndss-symposium.org/ndss-paper/should-i-trust-you-rethinking-the-principle-of-zone-based-isolation-dns-bailiwick-checking/

    Post summary

    The user notes a recent paper on DNS cache‑poisoning vulnerabilities and lists three CVEs, but does not provide PoC, exploit, patch, or active exploitation details.

    15412113.3K
    4.4K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @OrangeMorishita CVE-2025-11411 (Unbound up to 1.24.1) enables poisoning of NS RRsets, risking domain hijacks. ⚠️ CVE-2025-59023 (PowerDNS Recursor) presents a specific cache poisoning vector, less detailed in results but tied to the paper's analysis. #Unbound #PowerDNS

    Post summary

    The tweet highlights DNS cache poisoning vulnerabilities in Unbound and PowerDNS Recursor, noting potential domain hijack risks, but does not mention active exploitation, PoC, or patches.

    1000044
    313 followersView on X
  • transilienceai@transilienceai
    General

    "Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick Checking" is a research paper published in October 2025 that analyzes cache poisoning vulnerabilities in major DNS resolvers, including CVE-2025-40778 (BIND), CVE-2025-11411 (Unbound), and CVE-2025-59023 (PowerDNS Recursor). 📅🔍 It critiques the traditional zone-based isolation (DNS bailiwick checking) principle, arguing it fails under certain conditions, enabling attackers to inject forged records into caches. #DNS #Security

    Post summary

    The text cites a 2025 research paper analyzing cache‑poisoning flaws in DNS resolvers and critiquing the bailiwick checking principle, but it does not provide PoC, exploit, active exploitation, patch, or debunking information.

    1000089
    313 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-59023 Crafted delegations or IP fragments can poison cached delegations in Recursor. https://www.cve.org/CVERecord?id=CVE-2025-59023

    Post summary

    The CVE involves delegation poisoning via crafted delegations or IP fragments in Recursor. No PoC, exploit, patch, or active exploitation is reported.

    00010370
    56.5K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH SEVERITY: CVE-2025-59023 (CVSS 8.2) PowerDNS Recursor vulnerable to cache poisoning via crafted delegations/IP fragments. Network-exploitable, no auth required. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/2yHL4GTMjw

    Post summary

    High‑severity cache‑poisoning vulnerability (CVE‑2025‑59023) in PowerDNS Recursor has been announced, with an immediate patch urged.

    00000547
    27 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-59023 - High Crafted delegations or IP fragments can poison cached delegations in Recursor. https://www.thehackerwire.com/vulnerability/CVE-2025-59023/ https://t.co/Hbbwcwx9AB

    Post summary

    The tweet announces CVE-2025-59023 as a high‑severity flaw that allows poisoning of cached delegations in Recursor via crafted delegations or IP fragments.

    0000074
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppowerdnsrecursor---

Explore more