CVE-2026-33260
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33260 is a denial-of-service vulnerability affecting the internal web server component of PowerDNS Authoritative Server, PowerDNS Recursor, and dnsdist. An unauthenticated remote attacker can send a crafted web request that triggers unlimited memory allocation, exhausting available memory and causing a denial of service. The internal web server is disabled by default, limiting the attack surface to deployments where it has been explicitly enabled. Affected versions include PowerDNS Authoritative 4.9.0–4.9.13 and 5.0.0–5.0.3, PowerDNS Recursor 5.2.0–5.2.8, 5.3.0–5.3.5, and 5.4.0, and dnsdist 1.9.0–1.9.12 and 2.0.0–2.0.3. It carries a CVSS v3.1 base score of 7.5 (High) per NVD, or 5.3 (Medium) per ENISA/GitHub Advisory (GitHub Advisory, PowerDNS Advisory 2026-05, dnsdist Advisory).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling): the internal web server fails to impose restrictions on memory allocation when processing incoming HTTP requests, allowing an attacker to trigger unbounded memory growth (GitHub Advisory). The vulnerability is network-accessible, requires no authentication or user interaction, and has low attack complexity — an attacker simply sends a specially crafted HTTP request to the exposed internal web server port. The Red Hat Bugzilla entry characterizes the issue as "insufficient input validation of internal webserver," suggesting the web server does not validate or limit the size or structure of incoming request data before allocating memory (bugzilla.redhat.com). No public proof-of-concept code has been identified.

Impact

Successful exploitation causes memory exhaustion on the affected host, resulting in a denial of service that prevents the DNS server or load balancer from processing legitimate traffic. The impact is limited to availability — there is no confidentiality or integrity impact, and no evidence of lateral movement potential or data exposure (GitHub Advisory). Because the affected products (PowerDNS Authoritative, Recursor, and dnsdist) are critical DNS infrastructure components, a successful DoS attack could disrupt DNS resolution for all dependent services and clients (PowerDNS Advisory 2026-05, dnsdist Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is only possible when the internal web server feature has been explicitly enabled, which is not the default configuration, significantly reducing the effective attack surface.

Exploitation steps

  1. Reconnaissance: Identify hosts running PowerDNS Authoritative (4.9.0–4.9.13 or 5.0.0–5.0.3), PowerDNS Recursor (5.2.0–5.2.8, 5.3.0–5.3.5, or 5.4.0), or dnsdist (1.9.0–1.9.12 or 2.0.0–2.0.3) with the internal web server enabled. Scan for open HTTP ports commonly used by PowerDNS's internal web server (default port 8081 for Authoritative/Recursor, 8083 for dnsdist).
  2. Confirm web server availability: Send a basic HTTP GET request to the target port to confirm the internal web server is active and responding.
  3. Craft malicious request: Construct an HTTP request designed to trigger unbounded memory allocation — for example, a request with an oversized or malformed body, headers, or parameters that the web server processes without enforcing memory limits.
  4. Send request(s): Transmit the crafted request(s) to the target. The server allocates memory without restriction for each request, progressively exhausting available system memory.
  5. Achieve denial of service: Once memory is exhausted, the PowerDNS process becomes unresponsive or crashes, causing DNS resolution or traffic distribution to fail for all dependent clients (bugzilla.redhat.com, GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to the PowerDNS internal web server port (commonly TCP 8081 or 8083) from unexpected source IPs; high-volume or large HTTP requests targeting these ports.
  • Logs: PowerDNS or dnsdist logs showing a spike in web server request handling errors or out-of-memory conditions; system logs (e.g., /var/log/syslog, journalctl) recording OOM (Out of Memory) killer events targeting the PowerDNS or dnsdist process.
  • Process/System: Rapid increase in memory consumption by the pdns, pdns_recursor, or dnsdist process observable via top, htop, or monitoring tools; process crashes or restarts coinciding with unusual web server traffic.

Mitigation and workarounds

Vendor patches are available for all affected products. Upgrade to the following fixed versions: PowerDNS Authoritative 4.9.14 or 5.0.4+; PowerDNS Recursor 5.2.9, 5.3.6, or 5.4.1+; dnsdist 1.9.13 or 2.0.4+ (PowerDNS Advisory 2026-05, PowerDNS Recursor Advisory, dnsdist Advisory). As an immediate workaround, ensure the internal web server is disabled (the default configuration) by verifying that webserver=no or equivalent is set in your configuration. If the web server must remain enabled, restrict access to it using firewall rules to allow only trusted management IPs.

Community reactions

PowerDNS published coordinated security advisories on April 22, 2026 covering all three affected products (Authoritative, Recursor, and dnsdist), and the vulnerability was disclosed via the oss-security mailing list (oss-sec). Red Hat opened a tracking bug and assigned high severity, indicating downstream Linux distribution impact (bugzilla.redhat.com). Debian and openSUSE subsequently issued security updates for affected packages, and Tenable released Nessus detection plugins. Community reaction has been measured, reflecting the limited exploitability due to the web server being disabled by default.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management