Changelogs for 4.9.x
====================
+.. changelog::
+ :version: 4.9.16
+ :released: 25th of June 2026
+
+ This is release 4.9.16 of the Authoritative Server.
+ It contains a security fix only.
+
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x.
+
+ .. change::
+ :tags: Bug Fixes
+ :pullreq: 17591
+
+ Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server
+
.. changelog::
:version: 4.9.15
:released: 20th of May 2026
Changelogs for 5.0.x
====================
+.. changelog::
+ :version: 5.0.6
+ :released: 25th of June 2026
+
+ This is release 5.0.6 of the Authoritative Server.
+ It contains a security fix only.
+
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+
+ .. change::
+ :tags: Bug Fixes
+ :pullreq: 17590
+
+ Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server
+
.. changelog::
:version: 5.0.5
:released: 20th of May 2026
This is release 5.0.5 of the Authoritative Server.
It contains bug fixes and security fixes.
- Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x.
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
.. change::
:tags: Bug Fixes
This is release 5.0.4 of the Authoritative Server.
It contains security fixes only.
- Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 4.9.x.
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
.. change::
:tags: Bug Fixes
Changelogs for 5.1.x
====================
+.. changelog::
+ :version: 5.1.2
+ :released: 25th of June 2026
+
+ This is release 5.1.2 of the Authoritative Server.
+ It contains a security fix only.
+
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
+
+ .. change::
+ :tags: Bug Fixes
+ :pullreq: 17589
+
+ Fix PowerDNS Security Advisory 2026-07 for PowerDNS Authoritative Server
+
.. changelog::
:version: 5.1.1
:released: 8th of June 2026
This is release 5.1.1 of the Authoritative Server.
It contains an important bugfix for users of the LMDB backend.
- Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
.. change::
:tags: Bug Fixes
This is release 5.1.0 of the Authoritative Server.
It provides many small new features and improvements, as well as bug fixes.
- Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
.. change::
:tags: Improvements
It provides many small new features and improvements, as well as bug fixes,
including fixes for the PowerDNS Security Advisory 2026-05.
- Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
.. change::
:tags: New Features
This is release 5.1.0-alpha1 of the Authoritative Server.
It provides many small new features and improvements, as well as bug fixes.
- Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.0.x.
+ Please review the :doc:`Upgrade Notes <../upgrading>` before upgrading from versions < 5.1.x.
.. change::
:tags: New Features
-@ 86400 IN SOA pdns-public-ns1.powerdns.com. peter\.van\.dijk.powerdns.com. 2026060801 10800 3600 604800 10800
+@ 86400 IN SOA pdns-public-ns1.powerdns.com. peter\.van\.dijk.powerdns.com. 2026062501 10800 3600 604800 10800
@ 3600 IN NS pdns-public-ns1.powerdns.com.
@ 3600 IN NS pdns-public-ns2.powerdns.com.
auth-4.9.12.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
auth-4.9.13.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
auth-4.9.14.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html"
-auth-4.9.15.security-status 60 IN TXT "1 OK"
+auth-4.9.15.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html"
+auth-4.9.16.security-status 60 IN TXT "1 OK"
auth-5.0.0-alpha1.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
auth-5.0.0-beta1.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
auth-5.0.0.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
auth-5.0.2.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
auth-5.0.3.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"
auth-5.0.4.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-06.html"
-auth-5.0.5.security-status 60 IN TXT "1 OK"
+auth-5.0.5.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html"
+auth-5.0.6.security-status 60 IN TXT "1 OK"
auth-5.1.0-alpha1.security-status 60 IN TXT "3 Superseded pre-release (known vulnerabilities)"
auth-5.1.0-beta1.security-status 60 IN TXT "3 Unsupported pre-release (known vulnerabilities)"
-auth-5.1.0.security-status 60 IN TXT "1 OK"
-auth-5.1.1.security-status 60 IN TXT "1 OK"
+auth-5.1.0.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html"
+auth-5.1.1.security-status 60 IN TXT "3 Upgrade now, see https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-07.html"
+auth-5.1.2.security-status 60 IN TXT "1 OK"
; Auth Debian
auth-3.4.1-2.debian.security-status 60 IN TXT "3 Upgrade now, see https://docs.powerdns.com/authoritative/appendices/EOL.html"
--- /dev/null
+PowerDNS Security Advisory 2026-07: Insufficient input validation of internal web server
+========================================================================================
+
+- CVE: CVE-2026-42005
+- Date: 2026-06-25T00:00:00+01:00
+- Discovery date: 2026-04-25T00:00:00+01:00
+- Affects: PowerDNS Authoritative Server 3.4.0 up to and including 4.9.15, 5.0.5 and 5.1.1
+- Not affected: PowerDNS Authoritative Server 4.9.16, 5.0.6 and 5.1.2
+- Severity: Medium
+- Impact: Denial of service
+- Exploit: This problem can be triggered by a client sending crafted HTTP queries, but only if the internal webserver is enabled.
+- Risk of system compromise: None
+- Solution: Upgrade to patched version or do not enable the internal webserver
+- CWE: CWE-770
+- CVSS: 3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
+- Last affected: 4.9.15,5.0.5,5.1.1
+- First fixed: 4.9.16,5.0.6,5.1.2
+- Internal ID: 481
+
+An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
+
+`CVSS Score: 4.3 <https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L&version=3.1>`__
+
+The remedy is: upgrade to a patched version, or prevent network access to the internal webserver. In general for defense in-depth reasons we recommend making the internal web server only accessible to trusted clients.
+
+We would like to thank ilya rozentsvaig for bringing this issue to our attention.