CVE-2026-45557 Details
Description
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0.
A vulnerability in Technitium DNS Server prior to version 15.0 allows an attacker in control of a domain to induce the server to make excessive DNSSEC-related requests. This behavior can lead to increased network traffic, as the server aggressively attempts to retrieve missing RRSIG records or resolve discrepancies in DNSKEY records.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/TechnitiumSoftware/DnsServer/blo/master/CHANGELOG.md#version-150 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-138-02.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://www.cve.org/CVERecord?id=CVE-2026-45557 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-405 | Asymmetric Resource Consumption (Amplification) | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-406 | Insufficient Control of Network Message Volume (Network Amplification) | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-770 | Allocation of Resources Without Limits or Throttling | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |