CVE-2026-33598: Out-of-bounds read in cache inspection via Lua
A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33598?
CVE-2026-33598 has a high severity rating due to its potential to cause an out-of-bounds read.
How do I fix CVE-2026-33598?
To fix CVE-2026-33598, users should update PowerDNS DNSDist to the latest version that addresses this vulnerability.
Which versions of PowerDNS DNSDist are affected by CVE-2026-33598?
CVE-2026-33598 affects PowerDNS DNSDist versions between 1.9.0 and 1.9.13, as well as versions between 2.0.0 and 2.0.4.
What is the cause of CVE-2026-33598?
CVE-2026-33598 is caused by a crafted response that leads to an out-of-bounds read when specific Lua calls are made on a packet cache.
Is there a workaround for CVE-2026-33598?
Currently, the primary mitigation for CVE-2026-33598 is to apply the recommended software updates as there are no official workarounds.