CVE-2026-42000: Insufficient Validation of Names During AXFR
Published May 21, 2026
·Updated
Insufficient Validation of Names During AXFR
Affected Software
2 affected components
PowerDNS Authoritative<4.9.15
PowerDNS Authoritative>=5.0.0<5.0.5
Event History
May 21, 2026
CVE Published
via MITRE·09:25 AM
Data Sourced
via MITRE·09:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-42000?
The severity of CVE-2026-42000 is rated as high with a score of 8.6.
2
How do I fix CVE-2026-42000?
To fix CVE-2026-42000, update the PowerDNS Authoritative software to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2026-42000?
CVE-2026-42000 allows for insufficient validation of names during AXFR, potentially leading to command injection vulnerabilities.
4
Which software is affected by CVE-2026-42000?
CVE-2026-42000 affects the PowerDNS Authoritative software.
5
When was CVE-2026-42000 published?
CVE-2026-42000 was published on May 21, 2026.