PatchSiren cyber security CVE debrief
CVE-2026-45557 Technitium CVE debrief
CVE-2026-45557 is a denial-of-service issue in Technitium DNS Server where the resolver aggressively retries fetching missing RRSIG records or mismatched DNSKEY records. A domain controlled by an attacker can make a vulnerable system generate excessive network traffic. The vendor fix is in version 15.0.
- Vendor
- Technitium
- Product
- DNS Server
- CVSS
- MEDIUM 5.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-05-19
Who should care
Administrators and operators running Technitium DNS Server, especially systems that resolve external or attacker-controlled domains and environments that rely on DNSSEC validation.
Technical summary
According to the supplied NVD description, vulnerable Technitium DNS Server instances over-aggressively attempt to fetch missing RRSIG records or DNSKEY records that do not match. Because the behavior can be triggered by a domain under attacker control, the resolver may repeatedly generate outbound DNS traffic and consume network resources. The issue is scored as medium severity and is fixed in Technitium DNS Server 15.0.
Defensive priority
Medium priority. Patch promptly if you run Technitium DNS Server, especially on resolvers exposed to untrusted DNS queries or high-volume DNSSEC traffic.
Recommended defensive actions
- Upgrade Technitium DNS Server to version 15.0 or later.
- Verify every deployed instance is on the fixed version, including backups, replicas, and container images.
- Monitor for unusual outbound DNS traffic or repeated lookups involving RRSIG and DNSKEY records.
- Review logs for patterns of repeated DNSSEC-related retries that could indicate exposure to this issue.
- If immediate patching is not possible, reduce exposure by limiting untrusted query sources and closely watching resolver resource usage.
Evidence notes
This debrief is based on the supplied NVD record and its reference metadata. The record states that CVE-2026-45557 was published on 2026-05-19, that NVD status was 'Awaiting Analysis' at capture time, and that the issue affects Technitium DNS Server with a fix in 15.0. The supplied corpus did not include the full text of the referenced changelog or CSAF file, so this summary relies on the NVD description and reference pointers only.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45557 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45557
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45557 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45557
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/TechnitiumSoftware/DnsServer/blo/master/CHANGELOG.md
9119a7d8-5eab-497f-8521-727c672e3725
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-138-02.json
9119a7d8-5eab-497f-8521-727c672e3725
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.