CVE-2026-33260 Details
Description
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
A denial-of-service vulnerability has been identified in PowerDNS DNSdist versions through 2.0.3 and 1.9.12. The issue arises from the internal web server, which is disabled by default, allowing an attacker to send crafted HTTP requests that cause unlimited memory allocation. This excessive memory use can lead to a service crash.
Users can upgrade to PowerDNS DNSdist versions 1.9.13 or 2.0.4, where this vulnerability has been patched. Alternatively, the internal web server can be disabled or restricted to trusted clients.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| powerdns authoritative | >= 4.9.0, < 4.9.14 >= 5.0.0, < 5.0.4 |
CPE
Remediation
| |
| powerdns dnsdist | >= 1.9.0, < 1.9.13 >= 2.0.0, < 2.0.4 |
CPE
Remediation
| |
| powerdns recursor | >= 5.2.0, < 5.2.9 >= 5.3.0, < 5.3.6 5.4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 22, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | New CVE Received | [email protected] |