CVE-2026-33596: Powerdns Dnsdist

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend.

Affected products

  • Powerdns Dnsdist: from 1.9.0, before 1.9.13 (fixed in 1.9.13); from 2.0.0, before 2.0.4 (fixed in 2.0.4)

Published 2026-04-22. Last modified 2026-06-17.