{"api_version":"1","generated_at":"2026-07-23T20:19:38+00:00","cve":"CVE-2019-3807","urls":{"html":"https://cve.report/CVE-2019-3807","api":"https://cve.report/api/cve/CVE-2019-3807.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-3807","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-3807"},"summary":{"title":"CVE-2019-3807","description":"An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-01-29 17:29:00","updated_at":"2019-10-09 23:49:00"},"problem_types":["CWE-295"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3807","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3807","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1669151 – (CVE-2019-3807) CVE-2019-3807 pdns-recursor: Insufficient validation of DNSSEC signature","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-02.html","name":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-02.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"PowerDNS Security Advisory 2019-02: Insufficient validation of DNSSEC signatures — PowerDNS Recursor  documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-3807","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-3807","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"3807","vulnerable":"1","versionEndIncluding":"4.1.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"powerdns","cpe5":"recursor","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-3807","qid":"501114","title":"Alpine Linux Security Update for pdns-recursor"},{"cve":"CVE-2019-3807","qid":"505209","title":"Alpine Linux Security Update for pdns-recursor"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2019-3807","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"pdns-recursor","version":{"version_data":[{"version_value":"versions 4.1.x before 4.1.9"}]}}]},"vendor_name":"Power DNS"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation."}]},"impact":{"cvss":[[{"vectorString":"3.7/CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","version":"3.0"}]]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-345"}]}]},"references":{"reference_data":[{"name":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-02.html","refsource":"CONFIRM","url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2019-02.html"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3807","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3807"}]}},"nvd":{"publishedDate":"2019-01-29 17:29:00","lastModifiedDate":"2019-10-09 23:49:00","problem_types":["CWE-295"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.0","versionEndIncluding":"4.1.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"3807","Ordinal":"141416","Title":"CVE-2019-3807","CVE":"CVE-2019-3807","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"3807","Ordinal":"1","NoteData":"An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"3807","Ordinal":"2","NoteData":"2019-01-29","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"3807","Ordinal":"3","NoteData":"2019-01-29","Type":"Other","Title":"Modified"}]}}}