
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33257 is a denial-of-service vulnerability affecting the internal web server component of multiple PowerDNS products, including Authoritative Server, Recursor, and dnsdist. An unauthenticated attacker can send a specially crafted web request that triggers unlimited memory allocation, exhausting available memory and causing a denial of service. The internal web server is disabled by default, limiting the attack surface to deployments where it has been explicitly enabled. Affected versions include PowerDNS Authoritative 4.9.0–4.9.13 and 5.0.0–5.0.3, Recursor 5.2.0–5.2.8, 5.3.0–5.3.5, and 5.4.0, and dnsdist 1.9.0–1.9.12 and 2.0.0–2.0.3. The vulnerability was published on April 22, 2026, with a CVSS v3.1 base score of 7.5 (High) per NVD, or 5.3 (Medium) per ENISA/GitHub Advisory (GitHub Advisory, PowerDNS Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling): the internal web server fails to impose any restriction on the amount of memory it allocates when processing incoming HTTP requests (GitHub Advisory, Red Hat Bugzilla). An attacker with network access to the internal web server endpoint can send a crafted request that causes unbounded memory growth, ultimately crashing or rendering the service unavailable. No authentication is required, and the attack complexity is low. The vulnerability is only exploitable when the internal web server feature has been explicitly enabled, as it is disabled by default (PowerDNS Advisory).
Successful exploitation results in a denial of service against the affected PowerDNS component (Authoritative Server, Recursor, or dnsdist), causing the service to become unavailable due to memory exhaustion. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue. In environments where PowerDNS serves as critical DNS infrastructure, a successful attack could disrupt DNS resolution for dependent services and clients (GitHub Advisory, PowerDNS Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.012% (0.002% per GitHub Advisory), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is limited to deployments where the internal web server is explicitly enabled and network-accessible, which significantly reduces the effective attack surface.
/var/log/syslog, journalctl) recording OOM killer events targeting the PowerDNS process.pdns_server, pdns_recursor, or dnsdist process; abnormally high memory consumption by these processes prior to crash as observed via top, htop, or monitoring tools.Patches are available for all affected versions. Upgrade to the following fixed releases: PowerDNS Authoritative 4.9.14+ (for 4.9.x) or 5.0.4+ (for 5.0.x); PowerDNS Recursor 5.2.9+ (for 5.2.x), 5.3.6+ (for 5.3.x), or 5.4.1+ (for 5.4.x); dnsdist 1.9.13+ (for 1.9.x) or 2.0.4+ (for 2.0.x) (PowerDNS Advisory, dnsdist Advisory). As an immediate workaround, ensure the internal web server remains disabled unless explicitly required. If the web server must be enabled, implement network-level access controls (firewall rules, ACLs) to restrict access to trusted management hosts only (GitHub Advisory).
PowerDNS published coordinated security advisories on April 22, 2026, covering all three affected products (Authoritative, Recursor, and dnsdist) (PowerDNS Blog). The vulnerability was disclosed to the oss-security mailing list and picked up by Linux distribution security teams, including Red Hat and openSUSE, who issued their own advisories and package updates (Red Hat Bugzilla). Community discussion on Hacker News and security forums was limited, consistent with the moderate severity and restricted default attack surface of the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."