VDB
CVE-2026-33611
CVE-2026-33611
PUBLISHED
CVSS 6.5 MEDIUM
An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.
EPSS 0.01% · 1.7th percentile
Risk Scores
CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
EPSS Score
0.01%
1.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PowerDNS | Authoritative | 5.0.0, 4.9.0 |
Timeline
- Apr 22, 2026 CVE Published
- Apr 22, 2026 CVE Updated
- Apr 23, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score