
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33260 is a denial-of-service vulnerability affecting the internal web server component of PowerDNS Authoritative Server, PowerDNS Recursor, and dnsdist. An unauthenticated remote attacker can send a crafted web request that triggers unlimited memory allocation, exhausting available memory and causing a denial of service. The internal web server is disabled by default, limiting the attack surface to deployments where it has been explicitly enabled. Affected versions include PowerDNS Authoritative 4.9.0–4.9.13 and 5.0.0–5.0.3, PowerDNS Recursor 5.2.0–5.2.8, 5.3.0–5.3.5, and 5.4.0, and dnsdist 1.9.0–1.9.12 and 2.0.0–2.0.3. It carries a CVSS v3.1 base score of 7.5 (High) per NVD, or 5.3 (Medium) per ENISA/GitHub Advisory (GitHub Advisory, PowerDNS Advisory 2026-05, dnsdist Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling): the internal web server fails to impose restrictions on memory allocation when processing incoming HTTP requests, allowing an attacker to trigger unbounded memory growth (GitHub Advisory). The vulnerability is network-accessible, requires no authentication or user interaction, and has low attack complexity — an attacker simply sends a specially crafted HTTP request to the exposed internal web server port. The Red Hat Bugzilla entry characterizes the issue as "insufficient input validation of internal webserver," suggesting the web server does not validate or limit the size or structure of incoming request data before allocating memory (bugzilla.redhat.com). No public proof-of-concept code has been identified.
Successful exploitation causes memory exhaustion on the affected host, resulting in a denial of service that prevents the DNS server or load balancer from processing legitimate traffic. The impact is limited to availability — there is no confidentiality or integrity impact, and no evidence of lateral movement potential or data exposure (GitHub Advisory). Because the affected products (PowerDNS Authoritative, Recursor, and dnsdist) are critical DNS infrastructure components, a successful DoS attack could disrupt DNS resolution for all dependent services and clients (PowerDNS Advisory 2026-05, dnsdist Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is only possible when the internal web server feature has been explicitly enabled, which is not the default configuration, significantly reducing the effective attack surface.
/var/log/syslog, journalctl) recording OOM (Out of Memory) killer events targeting the PowerDNS or dnsdist process.pdns, pdns_recursor, or dnsdist process observable via top, htop, or monitoring tools; process crashes or restarts coinciding with unusual web server traffic.Vendor patches are available for all affected products. Upgrade to the following fixed versions: PowerDNS Authoritative 4.9.14 or 5.0.4+; PowerDNS Recursor 5.2.9, 5.3.6, or 5.4.1+; dnsdist 1.9.13 or 2.0.4+ (PowerDNS Advisory 2026-05, PowerDNS Recursor Advisory, dnsdist Advisory). As an immediate workaround, ensure the internal web server is disabled (the default configuration) by verifying that webserver=no or equivalent is set in your configuration. If the web server must remain enabled, restrict access to it using firewall rules to allow only trusted management IPs.
PowerDNS published coordinated security advisories on April 22, 2026 covering all three affected products (Authoritative, Recursor, and dnsdist), and the vulnerability was disclosed via the oss-security mailing list (oss-sec). Red Hat opened a tracking bug and assigned high severity, indicating downstream Linux distribution impact (bugzilla.redhat.com). Debian and openSUSE subsequently issued security updates for affected packages, and Tenable released Nessus detection plugins. Community reaction has been measured, reflecting the limited exploitability due to the web server being disabled by default.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."