Out-of-Bounds Read Vulnerability in PowerDNS
CVE-2026-33598

4.8MEDIUM

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-33598?

A vulnerability exists in PowerDNS that allows an out-of-bounds read condition when custom Lua code calls specific functions like getDomainListByAddress() or getAddressListByDomain() on a packet cache. This loophole could potentially lead to unauthorized data access, posing risks to the confidentiality and integrity of the affected systems. Users must ensure their installations are updated and review their Lua scripts to mitigate any associated risks.

Affected Version(s)

DNSdist 1.9.0 < 1.9.13

DNSdist 2.0.0 < 2.0.4

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.