CVE-2026-52684
Last modified
CVE-2026-52684 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| PowerDNS | Recursor | >= 0.0.0, < 5.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-52684?
How severe is CVE-2026-52684?
How do I fix CVE-2026-52684?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5266Exposure of Sensitive Information to an Unauthorized Actor v…2.3
- CVE-2026-5267Ciena Navigator Network Control Suite (NCS) contains an info…7.5
- CVE-2026-52673SQL Injection vulnerability in Cboard v.0.4.2 and before all…6.5
- CVE-2026-5268An authentication bypass vulnerability exists in the default…9.1
- CVE-2026-52680Apache Kyuubi REST batch multipart upload handling uses the …9.8
- CVE-2026-52681Sieve CPU resource usage is tracked in the compiled script, …3.1
- CVE-2026-52686The issue is a DNSSEC validation bypass where wildcard expan…3.7
- CVE-2026-52687An attacker that has valid credentials can select a compress…6.5
- CVE-2026-52688RRSIGs with too few labels can lead to bypass of DNSSEC wild…7.5
- CVE-2026-5269In Ciena's Navigator Network Control Suite (NCS) and Manage …9.8
- CVE-2026-52690Spoofing replies to Recursor might mark an IP of an authorit…5.9
- CVE-2026-52691** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of S…8.8
Are you affected by CVE-2026-52684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
