CVE-2026-33254: Powerdns Dnsdist
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default.
Affected products
- Powerdns Dnsdist: from 1.9.0, before 1.9.13 (fixed in 1.9.13); from 2.0.0, before 2.0.4 (fixed in 2.0.4)
Published 2026-04-22. Last modified 2026-06-17.