VDB
CVE-2026-33608
CVE-2026-33608
PUBLISHED
CVSS 7.400000095367432 HIGH
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.
EPSS 0.00% · 0.3th percentile
Risk Scores
CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.00%
0.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PowerDNS | Authoritative | 5.0.0, 4.9.0 |
Timeline
- Apr 22, 2026 CVE Published
- Apr 22, 2026 CVE Updated
- Apr 23, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score