CVE-2026-33595: DoQ/DoH3 excessive memory allocation
A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33595?
CVE-2026-33595 has been assigned a medium severity rating due to its potential for causing excessive memory allocation.
How do I fix CVE-2026-33595?
To fix CVE-2026-33595, update PowerDNS DNSDist to version 1.9.13 or 2.0.4 or later.
What are the affected versions for CVE-2026-33595?
CVE-2026-33595 affects PowerDNS DNSDist versions between 1.9.0 to 1.9.13 and 2.0.0 to 2.0.4.
What issue does CVE-2026-33595 cause?
CVE-2026-33595 allows a client to trigger excessive memory allocation through multiple error responses over a DoQ or DoH3 connection.
Who should be concerned about CVE-2026-33595?
Administrators using vulnerable versions of PowerDNS DNSDist should be concerned about CVE-2026-33595 due to its potential impact on resource utilization.