CVE-2026-42005Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 2 mentions (2026-06-25); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-26: 2Mentions · 2026-06-30: 2Mentions · 2026-07-05: 1Patch / Workaround · 2026-07-05: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 2Technical Details · 2026-07-05: 106-2506-2606-3007-05
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-252
Disclosure2
2026-06-262
Disclosure2
2026-06-302
Disclosure2
2026-07-051
Patch1
Full discourse7 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【注意喚起】PowerDNS Authoritative Serverの脆弱性情報が公開されました(CVE-2026-42005) https://jprs.jp/tech/security/2026-06-30-powerdns-auth.html

    Post summary

    The post announces that vulnerability details for PowerDNS Authoritative Server (CVE-2026-42005) have been published, serving as a disclosure announcement.

    02071840
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    CVE-2026-42005:内部Webサーバーが有効になっている場合(デフォルト無効)、特別に作成されたHTTPクエリを送るとシステムリソースを無制限に消費し、DoSにつながる。深刻度Medium。

    Post summary

    The text announces CVE-2026-42005, a medium‑severity denial‑of‑service vulnerability in the internal web server triggered by special HTTP requests.

    10011117
    4.5K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    CVE-2026-42005:Webサーバーが有効に設定されている場合(デフォルトでは無効)、特別に作成されたHTTPクエリでサーバーが落ちる。深刻度Medium。

    Post summary

    CVE-2026-42005 is a medium‑severity vulnerability that causes a web server to crash when a specially crafted HTTP query is sent, but no PoC, exploit tool, patch, or evidence of active exploitation is mentioned.

    01010306
    4.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42005 An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is di… https://www.cve.org/CVERecord?id=CVE-2026-42005

    Post summary

    The text discloses CVE-2026-42005 as a memory allocation flaw that can trigger a denial of service on an internal web server, with no PoC, exploit code, or patch information provided.

    00010982
    57.7K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-42005: PowerDNS Authoritative RCE — Detection and Patch Guide for Fedo… "A critical security advisory has been released for Fedora 43 systems running the PowerDNS…" 🔗 https://securityarsenal.com/blog/cve-2026-42005-powerdns-authoritative-rce-detection-and-patch-guide-for-fedora-43 #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    The text announces a critical advisory for CVE-2026-42005 affecting Fedora 43 PowerDNS instances, offering detection guidance and a patch approach.

    0000061
    19 followersView on X
  • ohhara_P🧐Slow life in the isekai@ohhara_shiojiri
    Disclosure

    PowerDNS Authoritative Serverの脆弱性情報が公開されました(CVE-2026-42005) https://jprs.jp/tech/security/2026-06-30-powerdns-auth.html

    Post summary

    An announcement that a vulnerability (CVE‑2026‑42005) affecting PowerDNS Authoritative Server has been publicly disclosed, with a reference link for further details.

    0000074
    2.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42005 An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is di… https://www.cve.org/CVERecord?id=CVE-2026-42005 ----- Traducción: CVE-2026-42005 Un … http://infoflow.cloud`

    Post summary

    CVE-2026-42005 is reported as a vulnerability that allows an attacker to trigger unlimited memory allocation in an internal web server, resulting in a denial of service.

    0000032
    89 followersView on X

Explore more