Denial of Service Vulnerability in PowerDNS Recursor
CVE-2026-33261

5.9MEDIUM

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-33261?

A zone transition from NSEC to NSEC3 in PowerDNS Recursor may lead to internal inconsistencies that result in a denial of service. This vulnerability can disrupt DNS resolution, impacting network availability and performance. It is crucial for administrators to apply necessary patches and updates to prevent potential exploitation.

Affected Version(s)

Recursor 5.4.0 < 5.4.1

Recursor 5.3.0 < 5.3.6

Recursor 5.2.0 < 5.2.9

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.