Resource exhaustion in PowerDNS Authoritative - CVE-2026-33610
Published: April 22, 2026
PowerDNS Authoritative
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in forward-dnsupdate when processing responses from a primary server during a forwarded dnsupdate operation. A remote attacker can act as a rogue primary server and send crafted responses to cause a denial of service.
Exploitation requires a secondary server to forward a DNS update request to the primary server.