VYPR
Medium severity4.4NVD Advisory· Published Apr 22, 2026· Updated Apr 27, 2026

CVE-2026-33601

CVE-2026-33601

Description

If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

Affected products

2
  • PowerDNS/Recursor2 versions
    cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*range: >=5.2.0,<5.2.9
    • cpe:2.3:a:powerdns:recursor:5.4.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.