Out-of-bounds read in dnsdist - CVE-2026-33599
Published: April 23, 2026
dnsdist
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in service discovery when processing crafted SVCB responses. A remote attacker can send a crafted SVCB response to cause a denial of service.
Exploitation requires DDR upgrade to be enabled via the autoUpgrade or auto_upgrade settings.