
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33610 is an uncontrolled resource consumption vulnerability in PowerDNS Authoritative Server that allows a rogue primary DNS server to cause file descriptor exhaustion and eventually a denial of service (DoS) on a PowerDNS secondary server when it forwards a DNS update request. The vulnerability was published on April 22, 2026, and affects PowerDNS Authoritative versions 4.9.0 through 4.9.13 and 5.0.0 through 5.0.3. It carries a CVSS v3.1 base score of 7.5 (High) per NVD, and 5.9 (Medium) per ENISA/GitHub Advisory, reflecting differing assessments of attack complexity (GitHub Advisory, PowerDNS Advisory).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and stems from improper handling of file descriptors during the DNS update forwarding process on PowerDNS secondary servers. When a secondary server forwards a DNS UPDATE request to a primary server, a rogue or malicious primary can manipulate the interaction to prevent proper file descriptor cleanup, causing descriptors to accumulate until the system limit is reached. Exploitation requires network-level access to act as or impersonate a primary server, but no authentication or user interaction is needed (GitHub Advisory, PowerDNS Advisory).
Successful exploitation results in file descriptor exhaustion on the affected PowerDNS secondary server, ultimately causing a denial of service that prevents the server from processing legitimate DNS queries and requests. There is no confidentiality or integrity impact — the attack is purely an availability concern. Organizations relying on affected secondary servers for DNS resolution could experience service outages affecting all downstream clients (GitHub Advisory, PowerDNS Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.016% (0.000160), placing it in the 1st percentile for exploitation likelihood within 30 days. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Feedly).
Too many open files, EMFILE errors in system or application logs).pdns_server process (observable via lsof -p <pid> | wc -l or /proc/<pid>/fd); system alerts from monitoring tools on file descriptor exhaustion.PowerDNS has released patched versions 4.9.14 and 5.0.4, which address this vulnerability; upgrading is the recommended remediation (PowerDNS Advisory). As a workaround, administrators should restrict DNS UPDATE forwarding to explicitly trusted and verified primary servers using access control lists, and implement network-level controls (firewalls, IP allowlisting) to limit which hosts can act as primary servers. Monitoring file descriptor usage on DNS servers for anomalies can provide early warning of exploitation attempts. Debian and Fedora package updates have also been issued for affected distributions (Linux Security Debian, Linux Security Fedora).
PowerDNS published a security advisory and blog post on April 22, 2026, disclosing the vulnerability and providing patched versions (PowerDNS Blog). The vulnerability was also disclosed on the oss-security mailing list and picked up by downstream Linux distributions including Debian and Fedora, which issued updated packages (oss-sec). No notable independent researcher commentary or significant social media discussion has been observed beyond standard vulnerability tracking and distribution advisories.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
pdns
devel
pdns
focal (esm-apps)
pdns
jammy
pdns
jammy (esm-apps)
pdns
noble
pdns
noble (esm-apps)
pdns
resolute
pdns
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."