Incomplete LDAP Query Escaping in PowerDNS Affects Domain Security
CVE-2026-33609

5.3MEDIUM

Key Information:

Vendor

Powerdns

Vendor
CVE Published:
22 April 2026

What is CVE-2026-33609?

This vulnerability arises from the incomplete escaping of LDAP queries when running with 8bit-dns enabled. It allows unauthorized users to execute queries on internal domain subtrees, potentially exposing sensitive information and compromising domain integrity. Users of PowerDNS are encouraged to review their configurations and implement necessary security measures to mitigate this issue.

Affected Version(s)

Authoritative 5.0.0 < 5.0.4

Authoritative 4.9.0 < 4.9.14

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.