openwrt ▾
›
openwrt-25.12 ▾
›
vulnerability
›
CVE-2026-33256
Component Overview
Vulnerability Overview
Name
CVE-2026-33256
Source
NVD (
link
)
Debian (
link
)
Description
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
CWEs
CWE-770
Published Date
Apr 22, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-03.html
Broken Link
Analysis
#
Affected Component
Analysis
pdns-recursor
Exploitable
Vulnerability Ratings
#
5.3
CVSSv31
7.5
CVSSv31
NaN
other
Others affected component
#
Name
Project
Project Version
Version
Status
pdns-recursor
openwrt
master
5.2.5-r1
Exploitable