Description
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6397-1 | pdns-recursor security update |
References
History
Thu, 23 Jul 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Powerdns
Powerdns recursor |
|
| Vendors & Products |
Powerdns
Powerdns recursor |
Thu, 23 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record. | |
| Title | Wildcard CNAME proof validation bypass | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OX
Published:
Updated: 2026-07-23T08:03:37.563Z
Reserved: 2026-06-08T08:05:31.707Z
Link: CVE-2026-52686
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T09:30:16Z
Weaknesses
No weakness.
Debian DSA