Impact
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. This flaw allows the allocation of arbitrary amounts of memory, which can exhaust system resources and force the service to become unreachable. The weakness is governed by the "Uncontrolled Memory Allocation" category of software security issues.
Affected Systems
The vulnerability affects the PowerDNS Recursor, a DNS recursive resolver. No specific version information is provided, implying that all current releases are potentially impacted until a patch is released.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector is likely remote, via a crafted HTTP request sent to the internal web server; however, the service is disabled by default, which mitigates immediate risk. If the internal web server has been enabled, the vulnerability could be abused by anyone who can reach that interface.
OpenCVE Enrichment