CVE-2026-33608
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-33608 is a code injection vulnerability in PowerDNS Authoritative Server that allows an unauthenticated remote attacker to corrupt the BIND backend configuration by sending a crafted DNS notify request. The flaw affects PowerDNS Authoritative versions 4.9.0 through 4.9.13 and 5.0.0 through 5.0.3. It was published on April 22, 2026, with patches released the same day. The CVSS v3.1 base score is reported as 9.8 (Critical) by NVD and 7.4 (High) by the GitHub Advisory Database and ENISA EUVD, reflecting differing assessments of attack complexity (GitHub Advisory, PowerDNS Advisory).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and stems from insufficient sanitization of domain names received via DNS NOTIFY requests in the BIND backend of PowerDNS Authoritative Server. When a notify request is processed, the server adds a new secondary domain to the BIND backend and regenerates its configuration file; however, the domain name is not properly sanitized, allowing an attacker to inject content that renders the configuration invalid. This corrupted configuration persists on disk, causing the backend to fail on the next service restart and requiring manual administrator intervention to recover (GitHub Advisory, PowerDNS Advisory). A technical write-up describing the incomplete domain name sanitization during notify processing is available from an independent researcher (Infinitsec).

Impact

Successful exploitation allows an unauthenticated remote attacker to corrupt the BIND backend configuration file of a PowerDNS Authoritative Server, rendering the DNS service inoperative upon the next restart and requiring manual remediation. The primary impact is a denial of service affecting DNS availability (high availability impact), with high integrity impact due to the persistent corruption of the backend configuration. Confidentiality is not directly affected by this vulnerability, but prolonged DNS outages could facilitate secondary attacks or disrupt dependent services (GitHub Advisory, PowerDNS Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.005%, indicating a very low near-term probability of exploitation. No threat actor attribution has been reported. Detection support is available via Qualys (detection ID 6275373) and Tenable Nessus plugins (PowerDNS Blog).

Exploitation steps

  1. Reconnaissance: Identify internet-facing PowerDNS Authoritative Server instances running versions 4.9.0–4.9.13 or 5.0.0–5.0.3 with the BIND backend enabled, using tools such as Shodan or Censys targeting DNS service banners.
  2. Craft malicious NOTIFY request: Construct a DNS NOTIFY request for a specially crafted domain name containing characters or sequences that, when written into the BIND backend configuration file, produce invalid or injected configuration syntax.
  3. Send the NOTIFY request: Transmit the crafted DNS NOTIFY packet to the target PowerDNS Authoritative Server (UDP/TCP port 53). No authentication or prior access is required.
  4. Trigger configuration corruption: The server processes the notify, adds the malicious secondary domain to the BIND backend, and rewrites the backend configuration file with the injected/invalid content.
  5. Achieve denial of service: Upon the next service restart (e.g., after a system reboot or manual restart), the BIND backend fails to load due to the corrupted configuration, taking the DNS service offline until an administrator manually corrects the configuration file (PowerDNS Advisory, Infinitsec).

Indicators of compromise

  • Network: Unexpected or unsolicited DNS NOTIFY requests (opcode 4) arriving from untrusted or external IP addresses on UDP/TCP port 53 targeting the PowerDNS Authoritative Server.
  • File System: Unexpected modifications to the BIND backend configuration file (e.g., named.conf or equivalent) with unusual or malformed domain entries; timestamps on configuration files inconsistent with legitimate administrative activity.
  • Logs: PowerDNS log entries showing new secondary domain additions triggered by NOTIFY requests from unexpected sources; error messages on service restart indicating invalid BIND backend configuration (e.g., parse errors in the backend config file).
  • Process/Service: PowerDNS Authoritative service failing to start after a restart with errors referencing the BIND backend configuration; repeated failed restart attempts logged by the init system (systemd/syslog) (PowerDNS Advisory).

Mitigation and workarounds

PowerDNS has released patched versions: 4.9.14 (for the 4.9.x branch) and 5.0.4 (for the 5.0.x branch). Administrators should upgrade immediately to one of these versions. As a temporary workaround until patching is complete, implement network-level access controls (e.g., firewall rules or PowerDNS allow-notify-from configuration) to restrict DNS NOTIFY requests to trusted secondary nameservers only. Regularly validate the integrity of the BIND backend configuration file as an additional defensive measure (PowerDNS Advisory, GitHub Advisory).

Community reactions

PowerDNS published an official security advisory and blog post on April 22, 2026, disclosing the vulnerability and providing patched versions (PowerDNS Blog). The vulnerability was also disclosed on the oss-security mailing list (oss-sec) and subsequently covered by Debian security advisories, with Debian DSA-6233-1 addressing the issue in the pdns package (Linux Security). No significant social media controversy or notable independent researcher commentary beyond the vendor advisory has been observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

pdns

Affected

sid

pdns: 5.0.4-1

Fixed

trixie

pdns: 4.9.14-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

pdns

Unknown

devel

pdns

Unknown

focal (esm-apps)

pdns

Unknown

jammy

pdns

Unknown

jammy (esm-apps)

pdns

Unknown

noble

pdns

Unknown

noble (esm-apps)

pdns

Unknown

resolute

pdns

Unknown

Alpine

Fixed

edge

pdns: 5.0.4-r0

Fixed

v3.23

pdns: 5.0.4-r0

Fixed

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86469MEDIUM5.3
  • Linux Debian logoLinux Debian
  • glib2-devel
NoYesSep 07, 2026
CVE-2026-79603MEDIUM4.3
  • Linux Debian logoLinux Debian
  • xen
NoNoSep 08, 2026
CVE-2026-79602NONEN/A
  • Linux Debian logoLinux Debian
  • xen
NoNoSep 08, 2026
CVE-2026-62437NONEN/A
  • Linux Debian logoLinux Debian
  • xen
NoNoSep 08, 2026
CVE-2026-16028NONEN/A
  • Linux Debian logoLinux Debian
  • libprotocol-http2-perl
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management