CVE-2026-33611

MEDIUM

Insufficient validation of HTTPS and SVCB records

Title source: cna
STIX 2.1

Description

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 0.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (2)
PowerDNS/Authoritative 4.9.0 - 4.9.14
PowerDNS/Authoritative 5.0.0 - 5.0.4
Published Apr 22, 2026
Tracked Since Apr 22, 2026