CVE-2026-33596: TCP backend stream ID overflow
A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33596?
The severity of CVE-2026-33596 has not been officially rated but is associated with potential disruption in query-response matching due to a stream ID overflow.
How do I fix CVE-2026-33596?
To fix CVE-2026-33596, upgrade PowerDNS DNSDist to version 1.9.13 or later for version 1.9.x, or version 2.0.4 or later for version 2.0.x.
What systems are affected by CVE-2026-33596?
CVE-2026-33596 affects PowerDNS DNSDist versions between 1.9.0 to 1.9.13 and 2.0.0 to 2.0.4.
What impact does CVE-2026-33596 have on PowerDNS DNSDist?
CVE-2026-33596 can cause a mismatch between queries and responses, potentially leading to disruptions in DNS services.
Is there a workaround for CVE-2026-33596?
Currently, there is no public workaround available for CVE-2026-33596; upgrading to a patched version is recommended.