Null Pointer Dereference in PowerDNS Due to Malicious Authoritative Server
CVE-2026-33600
4.4MEDIUM
What is CVE-2026-33600?
A security flaw in PowerDNS Recursor allows a malicious authoritative server to send a rogue Response Policy Zone (RPZ), resulting in a null pointer dereference. This occurs due to a missing consistency check, which can lead to a denial of service, ultimately disrupting the normal operation of the DNS service.
Affected Version(s)
Recursor 5.4.0 < 5.4.1
Recursor 5.3.0 < 5.3.6
Recursor 5.2.0 < 5.2.9
