CVE-2026-52684
Received Received - Intake

TTL Capping Bypass in Open-Xchange DNS Resolver

Vulnerability report for CVE-2026-52684, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: Open-Xchange

Description

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and in that case not used. So this case can only happen if almost expired records are used to refresh the authoritative NS records.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-23
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
powerdns recursor *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability occurs when the authoritative server responds very slowly and NS records expire before being refreshed. The TTL capping mechanism fails due to missing data in this edge case, which does not happen during normal resolution. It only affects scenarios where almost-expired records are used to refresh authoritative NS records.

Impact Analysis

The impact is limited due to its low severity. It may allow slightly outdated or incorrect NS records to be used temporarily, potentially leading to minor resolution inconsistencies or delays in DNS lookups.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it relates to DNS record expiration and TTL capping in PowerDNS Recursor. It is a low-severity issue with limited impact on data integrity or confidentiality.

Mitigation Strategies

Update PowerDNS Recursor to the latest version that includes the fix from the referenced pull request to prevent TTL capping failure during slow authoritative server responses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52684. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart