Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33608

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 7.4
CVSS3: 9.8
EPSS Низкий

Описание

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
Версия от 4.9.0 (включая) до 4.9.14 (исключая)
cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.4 (исключая)

EPSS

Процентиль: 31%
0.00383
Низкий

7.4 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.

CVSS3: 7.4
debian
4 месяца назад

An attacker can send a notify request that causes a new secondary doma ...

CVSS3: 7.4
github
4 месяца назад

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.

EPSS

Процентиль: 31%
0.00383
Низкий

7.4 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-94