{"id":"CVE-2026-33257","summary":"Insufficient input validation of internal webserver","details":"An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.","modified":"2026-08-12T15:32:34.961768Z","published":"2026-04-22T09:37:59.871Z","related":["SUSE-SU-2026:22319-1","openSUSE-SU-2026:10632-1","openSUSE-SU-2026:21015-1"],"database_specific":{"cna_assigner":"OX","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33257.json"},"references":[{"type":"WEB","url":"https://repo.powerdns.com/"},{"type":"ADVISORY","url":"https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.html"},{"type":"ADVISORY","url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-03.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33257.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33257"},{"type":"ADVISORY","url":"https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-04.html"},{"type":"PACKAGE","url":"https://github.com/PowerDNS/pdns"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powerdns/pdns","events":[{"introduced":"99d7f7a403baf29714a9f640c24f106c402c5891"},{"fixed":"425110ef9a566eb2763d82f4a90ae4f5d4b6f2d0"},{"introduced":"d1499af06af5dfdff785e9b0595ee692074dba6e"},{"fixed":"b6ee83de58b7354ff1596ac5146facef3efbf9a3"},{"introduced":"298a9d67fb760a12eabe89164f92fb814572aea8"},{"fixed":"642a2bb5b67b2bf5c856819273d8f41fecbc0da8"},{"introduced":"89747e81bc60d7950276d5fda3ca669fa81b7cf9"},{"fixed":"bfd0cbf4bf5c1f8757d0cd94c86ea88caf7b2f6d"},{"introduced":"544037cd123e8662877b5dc0b7963f5a094a2faf"},{"fixed":"b297bb729c002bc715a362fb0dd953e581c9055b"},{"introduced":"ff33413345dc6a826ff0f37f0c78cd60cdf15689"},{"fixed":"1d377042e08ae8843834f572882cf5e7933779a0"},{"introduced":"c95adbda8ce519923dfdbe7947d82a2692e18af9"},{"last_affected":"c95adbda8ce519923dfdbe7947d82a2692e18af9"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*","cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*","cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*","cpe:2.3:a:powerdns:recursor:5.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.9.0"},{"fixed":"4.9.14"},{"introduced":"5.0.0"},{"fixed":"5.0.4"},{"introduced":"1.9.0"},{"fixed":"1.9.13"},{"introduced":"2.0.0"},{"fixed":"2.0.4"},{"introduced":"5.2.0"},{"fixed":"5.2.9"},{"introduced":"5.3.0"},{"fixed":"5.3.6"},{"introduced":"5.4.0"},{"last_affected":"5.4.0"}]}}],"versions":["5.4.0","auth-4.9.13","rec-5.4.0-rc1","rec-5.4.0","rec-5.2.8","rec-5.3.4","auth-4.9.12","dnsdist-2.0.2","rec-5.3.1","rec-5.2.6","dnsdist-2.0.1","auth-4.9.11","dnsdist-1.9.11","auth-4.9.10","auth-4.9.9","rec-5.2.5","auth-4.9.8","rec-5.3.0","auth-4.9.7","rec-5.2.4","dnsdist-2.0.0","rec-5.2.2","auth-4.9.6","auth-4.9.5","dnsdist-1.9.10","dnsdist-1.9.9","rec-5.2.0","auth-4.9.4","dnsdist-1.9.8","auth-4.9.3","dnsdist-1.9.7","auth-4.9.2","dnsdist-1.9.6","dnsdist-1.9.5","auth-4.9.1","dnsdist-1.9.4","dnsdist-1.9.3","rec-5.0.3","dnsdist-1.9.2","dnsdist-1.9.1","auth-4.9.0","auth-4.9.0-beta2","dnsdist-1.9.0","auth-4.9.0-beta1","rec-5.0.1","rec-5.0.0-rc2","rec-5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33257.json","vanir_signatures_modified":"2026-08-12T15:32:34Z","vanir_signatures":[{"source":"https://github.com/powerdns/pdns/commit/642a2bb5b67b2bf5c856819273d8f41fecbc0da8","target":{"file":"pdns/dnscrypt.cc"},"deprecated":false,"digest":{"line_hashes":["152898936404715912717012814958473792269","4575082192570469972237185990035341899","177678008705605303260633753884530753700","136680451824217662945478382805808332729","204969285221527224213910579710674063651","66014210593085438182573307698386496097","17525951591113452044796585153110335921"],"threshold":0.9},"id":"CVE-2026-33257-2829cf85","signature_type":"Line","signature_version":"v1"},{"id":"CVE-2026-33257-4b79aae9","signature_type":"Function","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/642a2bb5b67b2bf5c856819273d8f41fecbc0da8","target":{"file":"pdns/dnscrypt.cc","function":"DNSCryptQuery::computePaddingSize"},"deprecated":false,"digest":{"function_hash":"172078194597412758162700597563448847475","length":706}},{"deprecated":false,"digest":{"line_hashes":["267164273993890695462681232822702173228","254147238750497149020354176624768531180","111833849558877957770686629013387565768","172795771022719102256161942256088786852","116846252582779990294504138599689757229","132209276398926440573610110361447772713"],"threshold":0.9},"id":"CVE-2026-33257-95ede998","signature_type":"Line","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/1d377042e08ae8843834f572882cf5e7933779a0","target":{"file":"pdns/recursordist/rpzloader.cc"}},{"id":"CVE-2026-33257-b8fc9376","signature_type":"Function","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/642a2bb5b67b2bf5c856819273d8f41fecbc0da8","target":{"file":"pdns/dnscrypt.cc","function":"DNSCryptQuery::encryptResponse"},"deprecated":false,"digest":{"function_hash":"219139187612696838153193600735147256736","length":3007}},{"source":"https://github.com/powerdns/pdns/commit/bfd0cbf4bf5c1f8757d0cd94c86ea88caf7b2f6d","target":{"file":"pdns/dnsdistdist/dnscrypt.cc"},"deprecated":false,"digest":{"line_hashes":["6864841829016440226917919286801415092","177254253808237988567579585374243740684","281318965586644528261302210434407655020","236182772979616684272007619339406923158","321739554045469880473225520600194266713","204969285221527224213910579710674063651","66014210593085438182573307698386496097","17525951591113452044796585153110335921"],"threshold":0.9},"id":"CVE-2026-33257-d901a0a8","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"276771802078087666188325581091504637136","length":839},"id":"CVE-2026-33257-e809c528","signature_type":"Function","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/bfd0cbf4bf5c1f8757d0cd94c86ea88caf7b2f6d","target":{"function":"DNSCryptQuery::computePaddingSize","file":"pdns/dnsdistdist/dnscrypt.cc"}},{"deprecated":false,"digest":{"line_hashes":["267164273993890695462681232822702173228","254147238750497149020354176624768531180","111833849558877957770686629013387565768","172795771022719102256161942256088786852","116846252582779990294504138599689757229","132209276398926440573610110361447772713"],"threshold":0.9},"id":"CVE-2026-33257-eff8fcee","signature_type":"Line","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/b297bb729c002bc715a362fb0dd953e581c9055b","target":{"file":"pdns/recursordist/rpzloader.cc"}},{"id":"CVE-2026-33257-f8ee4cee","signature_type":"Function","signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/bfd0cbf4bf5c1f8757d0cd94c86ea88caf7b2f6d","target":{"file":"pdns/dnsdistdist/dnscrypt.cc","function":"DNSCryptQuery::encryptResponse"},"deprecated":false,"digest":{"function_hash":"259782563136530440917701746095514260405","length":3491}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}