Use-after-free in PowerDNS Recursor - CVE-2026-33259
Published: April 22, 2026
PowerDNS Recursor
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in RPZ data handling when processing many concurrent transfers of the same RPZ. A remote privileged user can trigger many concurrent transfers of the same RPZ to cause a denial of service.
Exploitation normally requires a malfunctioning RPZ provider.