{"id":"CVE-2026-33258","summary":"Crafted zones can cause increased resource usage","details":"By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.","modified":"2026-08-12T15:32:35.561483Z","published":"2026-04-22T09:38:19.312Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33258.json","cna_assigner":"OX"},"references":[{"type":"WEB","url":"https://repo.powerdns.com/"},{"type":"ADVISORY","url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-03.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33258.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33258"},{"type":"PACKAGE","url":"https://github.com/PowerDNS/pdns"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/powerdns/pdns","events":[{"introduced":"544037cd123e8662877b5dc0b7963f5a094a2faf"},{"fixed":"b297bb729c002bc715a362fb0dd953e581c9055b"},{"introduced":"ff33413345dc6a826ff0f37f0c78cd60cdf15689"},{"fixed":"1d377042e08ae8843834f572882cf5e7933779a0"},{"introduced":"c95adbda8ce519923dfdbe7947d82a2692e18af9"},{"last_affected":"c95adbda8ce519923dfdbe7947d82a2692e18af9"}],"database_specific":{"cpe":["cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*","cpe:2.3:a:powerdns:recursor:5.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"5.2.0"},{"fixed":"5.2.9"},{"introduced":"5.3.0"},{"fixed":"5.3.6"},{"introduced":"5.4.0"},{"last_affected":"5.4.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["5.4.0","rec-5.4.0-rc1","rec-5.4.0","rec-5.2.8","rec-5.3.4","rec-5.3.1","rec-5.2.6","rec-5.2.5","rec-5.3.0","rec-5.2.4","rec-5.2.2","rec-5.2.0"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/1d377042e08ae8843834f572882cf5e7933779a0","target":{"file":"pdns/recursordist/rpzloader.cc"},"deprecated":false,"digest":{"line_hashes":["267164273993890695462681232822702173228","254147238750497149020354176624768531180","111833849558877957770686629013387565768","172795771022719102256161942256088786852","116846252582779990294504138599689757229","132209276398926440573610110361447772713"],"threshold":0.9},"id":"CVE-2026-33258-95ede998","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/powerdns/pdns/commit/b297bb729c002bc715a362fb0dd953e581c9055b","target":{"file":"pdns/recursordist/rpzloader.cc"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["267164273993890695462681232822702173228","254147238750497149020354176624768531180","111833849558877957770686629013387565768","172795771022719102256161942256088786852","116846252582779990294504138599689757229","132209276398926440573610110361447772713"]},"id":"CVE-2026-33258-eff8fcee","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33258.json","vanir_signatures_modified":"2026-08-12T15:32:35Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}