CVE-2026-33611

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*

History

12 May 2026, 20:16

Type Values Removed Values Added
References () https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-powerdns-2026-05.html - () https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-powerdns-2026-05.html - Broken Link
CPE cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*
First Time Powerdns authoritative
Powerdns

22 Apr 2026, 15:16

Type Values Removed Values Added
CWE CWE-190

22 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-22 14:16

Updated : 2026-05-12 20:16


NVD link : CVE-2026-33611

Mitre link : CVE-2026-33611

CVE.ORG link : CVE-2026-33611


JSON object : View

Products Affected

powerdns

  • authoritative
CWE
CWE-190

Integer Overflow or Wraparound