{"id":"CVE-2026-42005","summary":"Insufficient input validation of internal web server","details":"An attacker can send a web request that causes unlimited memory \nallocation in the internal web server, leading to a denial of service. \nThe internal web server is disabled by default.","modified":"2026-08-14T18:51:37.262730451Z","published":"2026-06-25T11:57:16.346Z","related":["SUSE-SU-2026:23123-1","SUSE-SU-2026:23146-1","openSUSE-SU-2026:11411-1","openSUSE-SU-2026:21533-1"],"database_specific":{"cna_assigner":"OX","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42005.json"},"references":[{"type":"WEB","url":"https://repo.powerdns.com/"},{"type":"ADVISORY","url":"https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-powerdns-2026-07.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42005.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42005"},{"type":"PACKAGE","url":"https://github.com/PowerDNS/pdns"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powerdns/pdns","events":[{"introduced":"99d7f7a403baf29714a9f640c24f106c402c5891"},{"fixed":"7c1b70088307490488d0db23ced174fcad9ff0a6"},{"introduced":"d1499af06af5dfdff785e9b0595ee692074dba6e"},{"fixed":"bedb98023c7c20eddaeb63662a72c22b1ed15c34"},{"introduced":"f6109dd21a7e7a936912a5c7605a88b4f10719b3"},{"fixed":"9872469c75619fd857e63f31aab165e63a6dbec5"}],"database_specific":{"extracted_events":[{"introduced":"4.9.0"},{"fixed":"4.9.16"},{"introduced":"5.0.0"},{"fixed":"5.0.6"},{"introduced":"5.1.0"},{"fixed":"5.1.2"}],"source":"AFFECTED_FIELD"}}],"versions":["rec-5.1.1","rec-5.1.0","rec-5.0.5","rec-5.0.3","rec-5.0.1","rec-5.0.0-rc2","rec-5.0.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["149977703169693183970481022797089936531","128800879354160129135192148672564007913","194495915763764426460250727679407693777","301358666311042758090520590971451344316","108333809648636550108848020263271164138","302283086660993946339744286960854591367","146485727435344565036667152563049843607","21473893049952292151124117765904740188","128387126165100483431975823158888248599","175913592699814803004011903524774806640","126464941360936261869796750946822632760","323024048001473663020295365652119218843","322343155045960585134841169695977094416","320963312289492138364242567080894622589","173213027477966697672281318542692063133","103778123790719189400834905417306033715","37268508562009860443609354301301880124","262138621126659433039107303462253244753","39375183591857516344602869033912555084","108333809648636550108848020263271164138","302283086660993946339744286960854591367","146485727435344565036667152563049843607","21473893049952292151124117765904740188","128387126165100483431975823158888248599","175913592699814803004011903524774806640","126464941360936261869796750946822632760","323024048001473663020295365652119218843","322343155045960585134841169695977094416","320963312289492138364242567080894622589","173213027477966697672281318542692063133","250583059997623998670205291640302319047","326218598847239084116976408860006675095","215297024700022141306993727489588481608","3074995750411330785293275916231266670"]},"id":"CVE-2026-42005-c17c52ca","signature_type":"Line","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/9872469c75619fd857e63f31aab165e63a6dbec5","target":{"file":"pdns/recursordist/recursor_cache.cc"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42005.json","vanir_signatures_modified":"2026-08-12T16:25:13Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}]}