CVE-2026-33599
EUVD-2026-2494122.04.2026, 14:16
A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| powerdns | dnsdist | 1.9.0 ≤ 𝑥 < 1.9.13 |
| powerdns | dnsdist | 2.0.0 ≤ 𝑥 < 2.0.4 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration