CVE-2026-33258: Crafted zones can cause increased resource usage
Published Apr 22, 2026
·Updated
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.
Affected Software
3 affected components
PowerDNS recursor>=5.2.0<5.2.9
PowerDNS recursor>=5.3.0<5.3.6
PowerDNS recursor=5.4.0
Event History
Apr 22, 2026
CVE Published
via MITRE·09:38 AM
Data Sourced
via MITRE·09:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Oct 18, 58290
Event
via NVD·07:07 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-33258?
The severity of CVE-2026-33258 is rated as high with a score of 7.5.
2
What is CVE-2026-33258 about?
CVE-2026-33258 involves crafted zones that can lead to increased resource usage due to the allocation of large entries in the negative and aggressive NSEC(3) caches.
3
Who is affected by CVE-2026-33258?
CVE-2026-33258 affects users of PowerDNS recursor when they publish or query crafted DNS zones.
4
What can an attacker do with CVE-2026-33258?
An attacker can exploit CVE-2026-33258 to manipulate DNS queries and cause excessive resource allocation on a vulnerable PowerDNS recursor.
5
How do I mitigate CVE-2026-33258?
To mitigate CVE-2026-33258, ensure that you are using the latest version of PowerDNS recursor, which includes fixes for this vulnerability.