Code Injection in PowerDNS Authoritative - CVE-2026-33608
Published: April 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt configuration data and cause a denial of service.
The vulnerability exists due to code injection in Bind autosecondary zone transfer handling when processing crafted notify packets. A remote attacker can send a crafted notify request to corrupt configuration data and cause a denial of service.
Exploitation requires the Bind backend in autosecondary mode.
Affected software
Debian Linux
pdns (Debian package)
How to mitigate CVE-2026-33608
pdns (Debian package) - update to 4.9.14-0+deb13u1