CVE-2026-33595 is a memory exhaustion vulnerability affecting DNS over QUIC (DoQ) and DNS over HTTP/3 (DoH3) implementations, where improper resource management allows unauthenticated remote attackers to trigger excessive memory allocation by generating multiple error responses over a single connection. The vulnerability carries a CVSS 3.1 score of 5.3 (Medium), with no authentication required and low attack complexity, resulting in limited availability impact through denial of service. The vulnerability has not been designated as a Known Exploited Vulnerability (KEV), shows minimal community engagement with an exceptionally low EPSS score of 0.0001, and presents a FAUCET Risk Score of 32.0 out of 100, indicating low exploitation risk and priority status. There is no evidence of active exploitation or publicly available exploit code at this time. Organizations should address this vulnerability through standard patching procedures when updates become available, prioritizing systems that expose DoQ or DoH3 endpoints to untrusted networks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.9.0, < 1.9.13CPE match | cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.4CPE match | cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.