CVE Tools

Authoritative

32 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Authoritative, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Authoritative CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Authoritative CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-046
2026-055
2026-061
2026-070
2026-080
2026-090

Severity

How the 32 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical13%
  • High1238%
  • Medium1959%

Latest CVEs

The 15 most recently published vulnerabilities affecting Authoritative.

  1. CVE-2026-42005Insufficient input validation of internal web server4.3
  2. CVE-2026-41999Incorrect Behaviour of Views with TCP PROXY Requests4.8
  3. CVE-2026-42002Concurrency and locking defects in GSS-TSIG5.9
  4. CVE-2026-42001Insufficient Validation of Autoprimary SOA Queries7.5
  5. CVE-2026-42000Insufficient Validation of Names During AXFR6.8
  6. CVE-2026-42396Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail4.9
  7. CVE-2026-33611Insufficient validation of HTTPS and SVCB records6.5
  8. CVE-2026-33610Possible file descriptor exhaustion in forward-dnsupdate5.9
  9. CVE-2026-33609LDAP DN injection5.3
  10. CVE-2026-33608Incomplete domain name sanitization during7.4
  11. CVE-2026-33260Insufficient input validation of internal webserver5.3
  12. CVE-2026-33257Insufficient input validation of internal webserver5.3
  13. CVE-2020-24698An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might be able to cause a double-free, leading to a cr...9.8
  14. CVE-2020-24697An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can cause a denial of service by sending crafted quer...7.5
  15. CVE-2020-24696An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can trigger a race condition leading to a crash, or p...8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store