An issue has been found in PowerDNS Recursor where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.
This issue has been assigned CVE-2019-3807 by Red Hat.
PowerDNS Recursor from 4.1.0 up to and including 4.1.8 is affected.
We would like to thank Ralph Dolmans and George Thessalonikefs of NLNetLabs for finding and subsequently reporting this issue!