Vulnerability in PowerDNS Affecting DNS Resolution Services
CVE-2026-33599

3.1LOW

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-33599?

A vulnerability exists in PowerDNS's dnsdist that allows a malicious backend to send a maliciously crafted SVCB response to requests made through the Discovery of Designated Resolvers (DDR). This scenario may occur when utilizing the options for autoUpgrade in either Lua or YAML configurations. It's important to note that DDR upgrades are not enabled by default, which adds to the risk when these settings are employed. Administrators should ensure that only trusted backends are configured to safeguard their DNS resolution services.

Affected Version(s)

DNSdist 1.9.0 < 1.9.13

DNSdist 2.0.0 < 2.0.4

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.