Review reviewHigh
CVE-2026-52688
PowerDNS Recursor
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
- CVSS
- 7.5
- EPSS
- 0.13% 2.73% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.23
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
The CVSS severity warrants an early asset and exposure review.
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Confirm exposure before applying a vendor-supported change.
Confirm that PowerDNS Recursor and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.