Home

Description

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.

PUBLISHED Reserved 2026-03-23 | Published 2026-04-22 | Updated 2026-04-22 | Assigner OX




HIGH: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Problem types

Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

5.0.0 (semver) before 5.0.4
affected

4.9.0 (semver) before 4.9.14
affected

Credits

Vitaly Simonovich finder

References

docs.powerdns.com/...powerdns-advisory-powerdns-2026-05.html

cve.org (CVE-2026-33608)

nvd.nist.gov (CVE-2026-33608)

Download JSON