CVE-2026-33594: Powerdns Dnsdist
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection.
Affected products
- Powerdns Dnsdist: from 1.9.0, before 1.9.13 (fixed in 1.9.13); from 2.0.0, before 2.0.4 (fixed in 2.0.4)
Published 2026-04-22. Last modified 2026-06-17.