CVE detail
CVE-2026-33260
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
- https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-04.htmlwww.dnsdist.org
No excerpt available.
Vendor Advisorywww.dnsdist.orgApr 22, 2026, 10:16 AM - https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-03.htmldocs.powerdns.com
No excerpt available.
Vendor Advisorydocs.powerdns.comApr 22, 2026, 10:16 AM - https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-2026-05.htmldocs.powerdns.com
No excerpt available.
Vendor Advisorydocs.powerdns.comApr 22, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-33257CVSS 5.3 · Medium
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by defau…
- CVE-2026-33595CVSS 5.3 · Medium
A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until…
- CVE-2026-33594CVSS 5.3 · Medium
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will…
- CVE-2026-33254CVSS 5.3 · Medium
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are di…
- CVE-2026-33258CVSS 5.3 · Medium
By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.
- CVE-2026-33256CVSS 5.3 · Medium
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by defau…