CVE-2026-33599
EUVD-2026-2494122.04.2026, 14:16
A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| powerdns | dnsdist | 1.9.0 ≤ 𝑥 < 1.9.13 | CNA |
| powerdns | dnsdist | 2.0.0 ≤ 𝑥 < 2.0.4 | CNA |
Debian Releases
Common Weakness Enumeration