Memory Allocation Vulnerability in PowerDNS DoH Client
CVE-2026-33594

5.3MEDIUM

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-33594?

A vulnerability exists in PowerDNS DNSDist where clients can inadvertently trigger excessive memory allocation. This occurs when multiple queries are sent to an overloaded DNS-over-HTTPS (DoH) backend, leading to a backlog of queries that cannot be released until the connection is closed. This situation may result in degraded performance and increased resource consumption. It is crucial for users to examine their configurations and monitor their DNS traffic to mitigate potential impacts.

Affected Version(s)

DNSdist 1.9.0 < 1.9.13

DNSdist 2.0.0 < 2.0.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mehtab Zafar
.