
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33594 is a denial-of-service vulnerability in PowerDNS dnsdist caused by excessive memory allocation in the DNS-over-HTTPS (DoH) backend. An unauthenticated remote client can trigger unbounded memory growth by flooding an overloaded DoH backend with queries that accumulate in a buffer and are not released until the connection ends. Affected versions include dnsdist 1.9.0 through 1.9.12 and 2.0.0 through 2.0.3. It was disclosed on April 22, 2026, with a CVSS v3.1 base score of 7.5 (High) per NVD, or 5.3 (Moderate) per GitHub Advisory (GitHub Advisory, PowerDNS Blog).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling): dnsdist does not impose restrictions on the number of pending queries buffered when routing to an overloaded DoH backend. When the backend is slow or saturated, incoming queries queue in memory without being released until the TCP/HTTP connection terminates, allowing an attacker to drive memory consumption arbitrarily high. No authentication or special privileges are required, and the attack complexity is low since any network-accessible client can initiate the condition (GitHub Advisory, PowerDNS Advisory).
Successful exploitation results in a denial-of-service condition through memory exhaustion on the dnsdist instance. There is no confidentiality or integrity impact — the vulnerability is limited to availability. An attacker who sustains the attack long enough can exhaust system memory, potentially crashing the dnsdist process or degrading DNS resolution service for all legitimate users relying on the affected DoH backend (GitHub Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code is known, and there is no evidence of in-the-wild exploitation as of the disclosure date (PowerDNS Blog). The EPSS score is approximately 0.01%, indicating a very low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported.
top, htop, or system monitoring agents; potential OOM-killer events in kernel logs (dmesg) targeting the dnsdist process.Upgrade dnsdist to version 1.9.13 or later (for the 1.9.x branch) or 2.0.4 or later (for the 2.0.x branch), which contain the fix for this vulnerability (PowerDNS Advisory, GitHub Advisory). As interim mitigations, implement rate limiting on DoH connections and queries per client at the network or application layer, and configure connection limits to restrict the number of concurrent DoH connections from individual clients. Monitor memory usage on dnsdist instances and set alerts for abnormal consumption patterns. Debian and openSUSE have also issued updated packages for their distributions (Linux Security).
PowerDNS published a security advisory and blog post on April 22, 2026, disclosing the vulnerability and providing patched versions (PowerDNS Blog). Red Hat tracked the issue via Bugzilla and assessed it as high severity (Red Hat Bugzilla). Debian and openSUSE subsequently issued distribution-level security updates. No notable independent researcher commentary or significant social media discussion has been observed beyond standard vulnerability tracking.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
dnsdist
devel
dnsdist
focal (esm-apps)
dnsdist
jammy
dnsdist
jammy (esm-apps)
dnsdist
noble
dnsdist
noble (esm-apps)
dnsdist
resolute
dnsdist
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."