CVE-2026-33260: Powerdns Authoritative
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
Affected products
- Powerdns Authoritative: from 4.9.0, before 4.9.14 (fixed in 4.9.14); from 5.0.0, before 5.0.4 (fixed in 5.0.4)
- Powerdns Dnsdist: from 1.9.0, before 1.9.13 (fixed in 1.9.13); from 2.0.0, before 2.0.4 (fixed in 2.0.4)
- Powerdns Recursor: from 5.2.0, before 5.2.9 (fixed in 5.2.9); from 5.3.0, before 5.3.6 (fixed in 5.3.6); version 5.4.0 only
Published 2026-04-22. Last modified 2026-06-17.