Medium severity5.3NVD Advisory· Published Apr 22, 2026· Updated Jun 17, 2026
CVE-2026-33257
CVE-2026-33257
Description
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- osv-coords2 versionspkg:rpm/opensuse/dnsdist&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/dnsdist&distro=openSUSE%20Tumbleweed
< 1.9.13-160000.1.1+ 1 more
- (no CPE)range: < 1.9.13-160000.1.1
- (no CPE)range: < 2.0.5-1.1
Patches
Vulnerability mechanics
References
3- docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.htmlnvdVendor Advisory
- docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-03.htmlnvdBroken LinkVendor Advisory
- www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-04.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.