{"api_version":"1","generated_at":"2026-07-23T20:19:18+00:00","cve":"CVE-2019-3806","urls":{"html":"https://cve.report/CVE-2019-3806","api":"https://cve.report/api/cve/CVE-2019-3806.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-3806","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-3806"},"summary":{"title":"CVE-2019-3806","description":"An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-01-29 17:29:00","updated_at":"2020-10-19 17:45:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-01.html","name":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-01.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"PowerDNS Security Advisory 2019-01: Lua hooks are not applied in certain configurations — PowerDNS Recursor  documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3806","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3806","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1669421 – (CVE-2019-3806) CVE-2019-3806 pdns-recursor: Lua hooks are not applied in certain configuration","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-3806","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-3806","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"3806","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"3806","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-3806","qid":"501114","title":"Alpine Linux Security Update for pdns-recursor"},{"cve":"CVE-2019-3806","qid":"505209","title":"Alpine Linux Security Update for pdns-recursor"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2019-3806","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"pdns-recursor","version":{"version_data":[{"version_value":"versions after 4.1.3 before 4.1.9"}]}}]},"vendor_name":"Power DNS"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua."}]},"impact":{"cvss":[[{"vectorString":"5.4/CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H","version":"3.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-358"}]}]},"references":{"reference_data":[{"name":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-01.html","refsource":"CONFIRM","url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-01.html"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3806","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3806"}]}},"nvd":{"publishedDate":"2019-01-29 17:29:00","lastModifiedDate":"2020-10-19 17:45:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.4","versionEndExcluding":"4.1.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"3806","Ordinal":"141415","Title":"CVE-2019-3806","CVE":"CVE-2019-3806","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"3806","Ordinal":"1","NoteData":"An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"3806","Ordinal":"2","NoteData":"2019-01-29","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"3806","Ordinal":"3","NoteData":"2019-01-29","Type":"Other","Title":"Modified"}]}}}