← Back

CVE-2026-33260

nvd nist
Published: Apr 22, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Affected (7)

3 products
Authoritative
Dnsdist
Recursor
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Powerdns
From 4.9.0 to 4.9.14
From 5.0.0 to 5.0.4
Powerdns
From 1.9.0 to 1.9.13
From 2.0.0 to 2.0.4
Powerdns
From 5.2.0 to 5.2.9
From 5.3.0 to 5.3.6
Version 5.4.0

Timeline

No history available yet.