
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33608 is a code injection vulnerability in PowerDNS Authoritative Server that allows an unauthenticated remote attacker to corrupt the BIND backend configuration by sending a crafted DNS notify request. The flaw affects PowerDNS Authoritative versions 4.9.0 through 4.9.13 and 5.0.0 through 5.0.3. It was published on April 22, 2026, with patches released the same day. The CVSS v3.1 base score is reported as 9.8 (Critical) by NVD and 7.4 (High) by the GitHub Advisory Database and ENISA EUVD, reflecting differing assessments of attack complexity (GitHub Advisory, PowerDNS Advisory).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and stems from insufficient sanitization of domain names received via DNS NOTIFY requests in the BIND backend of PowerDNS Authoritative Server. When a notify request is processed, the server adds a new secondary domain to the BIND backend and regenerates its configuration file; however, the domain name is not properly sanitized, allowing an attacker to inject content that renders the configuration invalid. This corrupted configuration persists on disk, causing the backend to fail on the next service restart and requiring manual administrator intervention to recover (GitHub Advisory, PowerDNS Advisory). A technical write-up describing the incomplete domain name sanitization during notify processing is available from an independent researcher (Infinitsec).
Successful exploitation allows an unauthenticated remote attacker to corrupt the BIND backend configuration file of a PowerDNS Authoritative Server, rendering the DNS service inoperative upon the next restart and requiring manual remediation. The primary impact is a denial of service affecting DNS availability (high availability impact), with high integrity impact due to the persistent corruption of the backend configuration. Confidentiality is not directly affected by this vulnerability, but prolonged DNS outages could facilitate secondary attacks or disrupt dependent services (GitHub Advisory, PowerDNS Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.005%, indicating a very low near-term probability of exploitation. No threat actor attribution has been reported. Detection support is available via Qualys (detection ID 6275373) and Tenable Nessus plugins (PowerDNS Blog).
named.conf or equivalent) with unusual or malformed domain entries; timestamps on configuration files inconsistent with legitimate administrative activity.PowerDNS has released patched versions: 4.9.14 (for the 4.9.x branch) and 5.0.4 (for the 5.0.x branch). Administrators should upgrade immediately to one of these versions. As a temporary workaround until patching is complete, implement network-level access controls (e.g., firewall rules or PowerDNS allow-notify-from configuration) to restrict DNS NOTIFY requests to trusted secondary nameservers only. Regularly validate the integrity of the BIND backend configuration file as an additional defensive measure (PowerDNS Advisory, GitHub Advisory).
PowerDNS published an official security advisory and blog post on April 22, 2026, disclosing the vulnerability and providing patched versions (PowerDNS Blog). The vulnerability was also disclosed on the oss-security mailing list (oss-sec) and subsequently covered by Debian security advisories, with Debian DSA-6233-1 addressing the issue in the pdns package (Linux Security). No significant social media controversy or notable independent researcher commentary beyond the vendor advisory has been observed.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
pdns
devel
pdns
focal (esm-apps)
pdns
jammy
pdns
jammy (esm-apps)
pdns
noble
pdns
noble (esm-apps)
pdns
resolute
pdns
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."