Denial of Service Vulnerability in PowerDNS Server by PowerDNS
CVE-2026-33257

5.3MEDIUM

Key Information:

Vendor

Powerdns

Vendor
CVE Published:
22 April 2026

What is CVE-2026-33257?

A security flaw has been identified in the PowerDNS server, allowing attackers to send specially crafted web requests that can lead to unlimited memory allocation in the internal web server. This excessive memory usage can disrupt the service, causing a denial of service for legitimate users. While the internal web server is disabled by default, administrators should take precautions to ensure their deployments are secure against potential exploitation.

Affected Version(s)

Authoritative 5.0.0 < 5.0.4

Authoritative 4.9.0 < 4.9.14

DNSdist 1.9.0 < 1.9.13

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vitaly Simonovich
.