PatchSiren cyber security CVE debrief
CVE-2026-27853 Powerdns CVE debrief
CVE-2026-27853 is a MEDIUM severity vulnerability in Powerdns Dnsdist that could allow an attacker to trigger an out-of-bounds write via crafted DNS responses. The vulnerability exists in the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. A successful exploit could lead to a crash resulting in denial of service. Users of affected versions should review and apply patches or mitigations to prevent potential denial of service attacks.
- Vendor
- Powerdns
- Product
- Dnsdist
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-31
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-03-31
- Advisory updated
- 2026-07-25
Who should care
Users of Powerdns Dnsdist versions 1.9.0 to 1.9.12 and 2.0.0 to 2.0.3 should apply patches or mitigations to prevent potential denial of service attacks. Security teams and operators managing DNS infrastructure should review the vulnerability and take action to protect exposed systems.
Technical summary
The vulnerability is caused by an out-of-bounds write that can occur when crafted DNS responses are sent to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. This can lead to a crash and denial of service. The CVSS score is 5.9 with a vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H. Affected product deployments should be reviewed for exposure and patched or mitigated accordingly.
Defensive priority
Apply patches or mitigations to prevent potential denial of service attacks. Review compensating controls for exposed systems while remediation is scheduled and verified.
Recommended defensive actions
- Apply patches or updates from the vendor
- Implement compensating controls such as monitoring and exception tracking
- Review and update custom Lua code to prevent exploitation
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record was published on 2026-03-31T12:16:27.917Z and last modified on 2026-07-25T10:10:00.167Z. The NVD entry is currently Analyzed. Evidence is limited to public sources and may not reflect the full scope or impact of this vulnerability. Defenders should verify affected systems and apply patches or mitigations accordingly.
Official resources
-
CVE-2026-27853 CVE record
CVE.org
-
CVE-2026-27853 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T12:16:27.917Z and has not been modified since then. The NVD entry is currently Analyzed.