CVE-2026-33602: Powerdns Dnsdist

High severity, CVSS 8.2. EPSS: 1.2% chance of exploitation in the next 30 days.

A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service.

Affected products

  • Powerdns Dnsdist: from 1.9.0, before 1.9.13 (fixed in 1.9.13); from 2.0.0, before 2.0.4 (fixed in 2.0.4)

Published 2026-04-22. Last modified 2026-06-17.