VYPR
Medium severity5.3NVD Advisory· Published Apr 22, 2026· Updated Apr 27, 2026

CVE-2026-33260

CVE-2026-33260

Description

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Affected products

4
  • cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
    Range: >=4.9.0,<4.9.14
  • cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*
    Range: >=1.9.0,<1.9.13
  • PowerDNS/Recursor2 versions
    cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*range: >=5.2.0,<5.2.9
    • cpe:2.3:a:powerdns:recursor:5.4.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.