CVE-2026-33257
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33257 is a denial-of-service vulnerability affecting the internal web server component of multiple PowerDNS products, including Authoritative Server, Recursor, and dnsdist. An unauthenticated attacker can send a specially crafted web request that triggers unlimited memory allocation, exhausting available memory and causing a denial of service. The internal web server is disabled by default, limiting the attack surface to deployments where it has been explicitly enabled. Affected versions include PowerDNS Authoritative 4.9.0–4.9.13 and 5.0.0–5.0.3, Recursor 5.2.0–5.2.8, 5.3.0–5.3.5, and 5.4.0, and dnsdist 1.9.0–1.9.12 and 2.0.0–2.0.3. The vulnerability was published on April 22, 2026, with a CVSS v3.1 base score of 7.5 (High) per NVD, or 5.3 (Medium) per ENISA/GitHub Advisory (GitHub Advisory, PowerDNS Advisory).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling): the internal web server fails to impose any restriction on the amount of memory it allocates when processing incoming HTTP requests (GitHub Advisory, Red Hat Bugzilla). An attacker with network access to the internal web server endpoint can send a crafted request that causes unbounded memory growth, ultimately crashing or rendering the service unavailable. No authentication is required, and the attack complexity is low. The vulnerability is only exploitable when the internal web server feature has been explicitly enabled, as it is disabled by default (PowerDNS Advisory).

Impact

Successful exploitation results in a denial of service against the affected PowerDNS component (Authoritative Server, Recursor, or dnsdist), causing the service to become unavailable due to memory exhaustion. There is no impact on confidentiality or data integrity — the vulnerability is purely an availability issue. In environments where PowerDNS serves as critical DNS infrastructure, a successful attack could disrupt DNS resolution for dependent services and clients (GitHub Advisory, PowerDNS Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.012% (0.002% per GitHub Advisory), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is limited to deployments where the internal web server is explicitly enabled and network-accessible, which significantly reduces the effective attack surface.

Exploitation steps

  1. Reconnaissance: Identify PowerDNS instances (Authoritative, Recursor, or dnsdist) with the internal web server enabled and accessible over the network, typically listening on a configured TCP port (e.g., 8081 by default for some products). Tools such as Shodan or Censys can be used to locate exposed endpoints.
  2. Craft malicious request: Prepare an HTTP request designed to trigger unbounded memory allocation in the internal web server. Based on the vulnerability description, this likely involves sending a request with an oversized or specially structured body/headers that the server attempts to buffer without limits.
  3. Send request: Transmit the crafted HTTP request to the target PowerDNS internal web server endpoint. No authentication credentials are required.
  4. Trigger DoS: The server allocates memory without restriction in response to the request, eventually exhausting available system memory and causing the PowerDNS process to crash or become unresponsive, resulting in a denial of service (PowerDNS Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to the PowerDNS internal web server port (default 8081 or as configured) from unexpected source IPs; high-volume or oversized HTTP requests targeting the management endpoint.
  • Logs: PowerDNS service logs showing memory allocation errors, out-of-memory (OOM) conditions, or abrupt process termination; system logs (e.g., /var/log/syslog, journalctl) recording OOM killer events targeting the PowerDNS process.
  • Process: Sudden crash or restart of the pdns_server, pdns_recursor, or dnsdist process; abnormally high memory consumption by these processes prior to crash as observed via top, htop, or monitoring tools.

Mitigation and workarounds

Patches are available for all affected versions. Upgrade to the following fixed releases: PowerDNS Authoritative 4.9.14+ (for 4.9.x) or 5.0.4+ (for 5.0.x); PowerDNS Recursor 5.2.9+ (for 5.2.x), 5.3.6+ (for 5.3.x), or 5.4.1+ (for 5.4.x); dnsdist 1.9.13+ (for 1.9.x) or 2.0.4+ (for 2.0.x) (PowerDNS Advisory, dnsdist Advisory). As an immediate workaround, ensure the internal web server remains disabled unless explicitly required. If the web server must be enabled, implement network-level access controls (firewall rules, ACLs) to restrict access to trusted management hosts only (GitHub Advisory).

Community reactions

PowerDNS published coordinated security advisories on April 22, 2026, covering all three affected products (Authoritative, Recursor, and dnsdist) (PowerDNS Blog). The vulnerability was disclosed to the oss-security mailing list and picked up by Linux distribution security teams, including Red Hat and openSUSE, who issued their own advisories and package updates (Red Hat Bugzilla). Community discussion on Hacker News and security forums was limited, consistent with the moderate severity and restricted default attack surface of the vulnerability.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-branding-upstream
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management