CVE-2026-33611

EUVD-2026-24951
An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 35.48%
Affected Products (NVD)
VendorProductVersion
powerdnsauthoritative
4.9.0 ≤
𝑥
< 4.9.14
powerdnsauthoritative
5.0.0 ≤
𝑥
< 5.0.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pdns
bookworm
vulnerable
forky
5.1.4-1
fixed
sid
5.1.4-1
fixed
trixie
4.9.16-0+deb13u1
fixed
trixie (security)
4.9.17-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pdns
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage