CVE-2026-33261mediumCWE-353

CVE-2026-33261: medium-severity vulnerability in PowerDNS Recursor

Null pointer accces in aggressive NSEC(3) cache

Published

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.9epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
PowerDNS · Recursor