CVE 6.5 MEDIUM

Insufficient validation of HTTPS and SVCB records_CVE-2026-33611

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Description

An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.

Basic Information

ID CVE-2026-33611
Source OX
Published Apr 22, 2026 at 14:01
Modified Apr 22, 2026 at 14:24

Affected Product

Vendor PowerDNS
Product Authoritative
Version 5.0.0
Affected Versions PowerDNS Authoritative 5.0.0
PowerDNS Authoritative 4.9.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.