An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
{
"cna_assigner": "OX",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33257.json"
}{
"cpe": [
"cpe:2.3:a:powerdns:authoritative:*:*:*:*:*:*:*:*",
"cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*",
"cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*",
"cpe:2.3:a:powerdns:recursor:5.4.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "4.9.0"
},
{
"fixed": "4.9.14"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.0.4"
},
{
"introduced": "1.9.0"
},
{
"fixed": "1.9.13"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.4"
},
{
"introduced": "5.2.0"
},
{
"fixed": "5.2.9"
},
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.6"
},
{
"introduced": "5.4.0"
},
{
"last_affected": "5.4.0"
}
],
"source": [
"CPE_RANGE",
"CPE_STRING"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33257.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"152898936404715912717012814958473792269",
"4575082192570469972237185990035341899",
"177678008705605303260633753884530753700",
"136680451824217662945478382805808332729",
"204969285221527224213910579710674063651",
"66014210593085438182573307698386496097",
"17525951591113452044796585153110335921"
],
"threshold": 0.9
},
"id": "CVE-2026-33257-2829cf85",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/powerdns/pdns/commit/642a2bb5b67b2bf5c856819273d8f41fecbc0da8",
"target": {
"file": "pdns/dnscrypt.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "172078194597412758162700597563448847475",
"length": 706
},
"id": "CVE-2026-33257-4b79aae9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/powerdns/pdns/commit/642a2bb5b67b2bf5c856819273d8f41fecbc0da8",
"target": {
"file": "pdns/dnscrypt.cc",
"function": "DNSCryptQuery::computePaddingSize"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"267164273993890695462681232822702173228",
"254147238750497149020354176624768531180",
"111833849558877957770686629013387565768",
"172795771022719102256161942256088786852",
"116846252582779990294504138599689757229",
"132209276398926440573610110361447772713"
],
"threshold": 0.9
},
"id": "CVE-2026-33257-95ede998",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/powerdns/pdns/commit/1d377042e08ae8843834f572882cf5e7933779a0",
"target": {
"file": "pdns/recursordist/rpzloader.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "219139187612696838153193600735147256736",
"length": 3007
},
"id": "CVE-2026-33257-b8fc9376",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/powerdns/pdns/commit/642a2bb5b67b2bf5c856819273d8f41fecbc0da8",
"target": {
"file": "pdns/dnscrypt.cc",
"function": "DNSCryptQuery::encryptResponse"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"6864841829016440226917919286801415092",
"177254253808237988567579585374243740684",
"281318965586644528261302210434407655020",
"236182772979616684272007619339406923158",
"321739554045469880473225520600194266713",
"204969285221527224213910579710674063651",
"66014210593085438182573307698386496097",
"17525951591113452044796585153110335921"
],
"threshold": 0.9
},
"id": "CVE-2026-33257-d901a0a8",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/powerdns/pdns/commit/bfd0cbf4bf5c1f8757d0cd94c86ea88caf7b2f6d",
"target": {
"file": "pdns/dnsdistdist/dnscrypt.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "276771802078087666188325581091504637136",
"length": 839
},
"id": "CVE-2026-33257-e809c528",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/powerdns/pdns/commit/bfd0cbf4bf5c1f8757d0cd94c86ea88caf7b2f6d",
"target": {
"file": "pdns/dnsdistdist/dnscrypt.cc",
"function": "DNSCryptQuery::computePaddingSize"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"267164273993890695462681232822702173228",
"254147238750497149020354176624768531180",
"111833849558877957770686629013387565768",
"172795771022719102256161942256088786852",
"116846252582779990294504138599689757229",
"132209276398926440573610110361447772713"
],
"threshold": 0.9
},
"id": "CVE-2026-33257-eff8fcee",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/powerdns/pdns/commit/b297bb729c002bc715a362fb0dd953e581c9055b",
"target": {
"file": "pdns/recursordist/rpzloader.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "259782563136530440917701746095514260405",
"length": 3491
},
"id": "CVE-2026-33257-f8ee4cee",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/powerdns/pdns/commit/bfd0cbf4bf5c1f8757d0cd94c86ea88caf7b2f6d",
"target": {
"file": "pdns/dnsdistdist/dnscrypt.cc",
"function": "DNSCryptQuery::encryptResponse"
}
}
]
"2026-08-12T15:32:34Z"