CVE-2026-33260
EUVD-2026-2472522.04.2026, 10:16
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| powerdns | authoritative | 4.9.0 ≤ 𝑥 < 4.9.14 |
| powerdns | authoritative | 5.0.0 ≤ 𝑥 < 5.0.4 |
| powerdns | dnsdist | 1.9.0 ≤ 𝑥 < 1.9.13 |
| powerdns | dnsdist | 2.0.0 ≤ 𝑥 < 2.0.4 |
| powerdns | recursor | 5.2.0 ≤ 𝑥 < 5.2.9 |
| powerdns | recursor | 5.3.0 ≤ 𝑥 < 5.3.6 |
| powerdns | recursor | 5.4.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dnsdist |
| ||||||||||||||
| pdns |
| ||||||||||||||
| pdns-recursor |
|