CVE-2026-33611: Insufficient validation of HTTPS and SVCB records
An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33611?
CVE-2026-33611 is considered a medium severity vulnerability due to the potential for LMDB database corruption.
How do I fix CVE-2026-33611?
To fix CVE-2026-33611, upgrade to PowerDNS Authoritative version 4.9.14 or higher, or 5.0.4 or higher.
What systems are affected by CVE-2026-33611?
CVE-2026-33611 affects PowerDNS Authoritative versions between 4.9.0 and 4.9.14, and between 5.0.0 and 5.0.4.
What causes CVE-2026-33611?
CVE-2026-33611 is caused by insufficient validation of HTTPS and SVCB records in the PowerDNS Authoritative REST API.
What are the consequences of exploiting CVE-2026-33611?
Exploiting CVE-2026-33611 can lead to the generation of invalid HTTPS or SVCB record data, resulting in LMDB database corruption.