Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33257

Опубликовано: 22 апр. 2026
Источник: debian

Описание

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dnsdistfixed2.0.4-1package
dnsdistend-of-lifebookwormpackage
dnsdistend-of-lifebullseyepackage
pdns-recursorfixed5.3.0-1package
pdns-recursorend-of-lifebookwormpackage
pdns-recursorend-of-lifebullseyepackage
pdnsfixed5.0.4-1package
pdnsend-of-lifebookwormpackage
pdnsend-of-lifebullseyepackage

Примечания

  • https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-04.html#cve-2026-33257-insufficient-input-validation-of-internal-webserver

  • https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-03.html#cve-2026-33257-insufficient-input-validation-of-internal-web-server

  • According to the advisory affects only PowerDNS Recursor up to and including 5.2.8,

  • Mark the first version in unstable after 5.2.9 as the fixed version.

  • https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html#insufficient-input-validation-of-internal-webserver

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

CVSS3: 5.3
nvd
4 месяца назад

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

CVSS3: 5.3
github
4 месяца назад

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

suse-cvrf
около 2 месяцев назад

Security update for dnsdist