Data Inconsistency and Resource Mismanagement in PowerDNS Recursor
CVE-2026-33259

5MEDIUM

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-33259?

The PowerDNS Recursor is susceptible to vulnerabilities caused by concurrent transfers of the same Response Policy Zone (RPZ). This condition may result in inconsistent RPZ data and cause the software to crash. Typically, such issues arise when there is a malfunctioning RPZ provider that allows multiple simultaneous transfers of the same zone, undermining the stability and reliability of the DNS resolver.

Affected Version(s)

Recursor 5.4.0 < 5.4.1

Recursor 5.3.0 < 5.3.6

Recursor 5.2.0 < 5.2.9

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haruto Kimura (Stella)
.