File Descriptor Exhaustion Vulnerability in PowerDNS Secondary Server by PowerDNS
CVE-2026-33610

5.9MEDIUM

Key Information:

Vendor

Powerdns

Vendor
CVE Published:
22 April 2026

What is CVE-2026-33610?

A vulnerability exists within PowerDNS where a secondary server may experience file descriptor exhaustion when forwarding DNS update requests from a rogue primary server. This can lead to a denial of service, significantly impacting the server's availability and performance. Administrators should monitor their DNS configurations and consider applying mitigation strategies as recommended by PowerDNS to safeguard against potential disruptions.

Affected Version(s)

Authoritative 5.0.0 < 5.0.4

Authoritative 4.9.0 < 4.9.14

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.