CVE-2026-33595: Powerdns Dnsdist

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection.

Affected products

  • Powerdns Dnsdist: from 1.9.0, before 1.9.13 (fixed in 1.9.13); from 2.0.0, before 2.0.4 (fixed in 2.0.4)

Published 2026-04-22. Last modified 2026-06-17.