recursor vulnerabilities
CVEs whose affected-version data names the recursor package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-59030High· 7.5An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
▾ Twilightpowerdns · recursorEPSS 0.58%via NVD
CVE-2025-59029Medium· 5.3An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
▾ Sunlitpowerdns · recursorEPSS 0.37%via NVD