# CVE-2026-42255

## Summary

- **CVE ID:** CVE-2026-42255
- **Severity:** HIGH
- **CVSS Score:** 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L)
- **CWE:** CWE-684
- **Published:** Apr 26, 2026
- **Last Modified:** Apr 27, 2026

## Description

Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

## Affected Products

- Technitium — DnsServer (0)

## References

- [CNA](https://github.com/TechnitiumSoftware/DnsServer/blob/master/CHANGELOG.md#technitium-dns-server-change-log)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 10.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._