CVE-2026-33256: Unbounded memory allocation by internal web server
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33256?
CVE-2026-33256 has a severity rating that indicates it can lead to denial of service due to unbounded memory allocation.
How do I fix CVE-2026-33256?
To address CVE-2026-33256, ensure the internal web server is disabled if not in use, or upgrade to a fixed version of PowerDNS recursor.
What software versions are affected by CVE-2026-33256?
CVE-2026-33256 affects PowerDNS recursor versions from 5.2.0 to 5.2.9, versions from 5.3.0 to 5.3.6, and 5.4.0.
Can CVE-2026-33256 impact my system?
Yes, CVE-2026-33256 can cause system instability and denial of service if exploited through unbounded memory allocation.
Is the internal web server enabled by default in PowerDNS recursor with CVE-2026-33256?
No, the internal web server is disabled by default in PowerDNS recursor, which mitigates the risk posed by CVE-2026-33256.