PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45557 Technitium CVE debrief

CVE-2026-45557 is a denial-of-service issue in Technitium DNS Server where the resolver aggressively retries fetching missing RRSIG records or mismatched DNSKEY records. A domain controlled by an attacker can make a vulnerable system generate excessive network traffic. The vendor fix is in version 15.0.

Vendor
Technitium
Product
DNS Server
CVSS
MEDIUM 5.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-19
Original CVE updated
2026-05-19
Advisory published
2026-05-19
Advisory updated
2026-05-19

Who should care

Administrators and operators running Technitium DNS Server, especially systems that resolve external or attacker-controlled domains and environments that rely on DNSSEC validation.

Technical summary

According to the supplied NVD description, vulnerable Technitium DNS Server instances over-aggressively attempt to fetch missing RRSIG records or DNSKEY records that do not match. Because the behavior can be triggered by a domain under attacker control, the resolver may repeatedly generate outbound DNS traffic and consume network resources. The issue is scored as medium severity and is fixed in Technitium DNS Server 15.0.

Defensive priority

Medium priority. Patch promptly if you run Technitium DNS Server, especially on resolvers exposed to untrusted DNS queries or high-volume DNSSEC traffic.

Recommended defensive actions

  • Upgrade Technitium DNS Server to version 15.0 or later.
  • Verify every deployed instance is on the fixed version, including backups, replicas, and container images.
  • Monitor for unusual outbound DNS traffic or repeated lookups involving RRSIG and DNSKEY records.
  • Review logs for patterns of repeated DNSSEC-related retries that could indicate exposure to this issue.
  • If immediate patching is not possible, reduce exposure by limiting untrusted query sources and closely watching resolver resource usage.

Evidence notes

This debrief is based on the supplied NVD record and its reference metadata. The record states that CVE-2026-45557 was published on 2026-05-19, that NVD status was 'Awaiting Analysis' at capture time, and that the issue affects Technitium DNS Server with a fix in 15.0. The supplied corpus did not include the full text of the referenced changelog or CSAF file, so this summary relies on the NVD description and reference pointers only.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45557 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45557

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45557 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45557

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TechnitiumSoftware/DnsServer/blo/master/CHANGELOG.md

    9119a7d8-5eab-497f-8521-727c672e3725

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-138-02.json

    9119a7d8-5eab-497f-8521-727c672e3725

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.