← Volver a CVEs
CVE-2026-33611
MEDIUM6.5
Descripcion
An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.
Detalles CVE
Puntuacion CVSS v3.16.5
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioNONE
Publicado4/22/2026
Ultima modificacion4/22/2026
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-190
Referencias
https://docs.powerdns.com/authoritative/security-advisories/powerdns-advisory-powerdns-2026-05.html(security@open-xchange.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.