CVE-2026-33611 PUBLISHED

Insufficient validation of HTTPS and SVCB records

Assigner: OX
Reserved: 23.03.2026 Published: 22.04.2026 Updated: 22.04.2026

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVSS Score: 6.5

Product Status

Vendor PowerDNS
Product Authoritative
Versions Default: unaffected
  • affected from 5.0.0 to 5.0.4 (excl.)
  • affected from 4.9.0 to 4.9.14 (excl.)

Credits

  • Tibs finder

References

Problem Types

  • Integer Overflow or Wraparound CWE