
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33600 is a NULL pointer dereference vulnerability in PowerDNS Recursor that can be triggered by a malicious authoritative server sending a specially crafted Response Policy Zone (RPZ), resulting in a denial of service. It affects PowerDNS Recursor versions 5.2.0 through 5.2.8, 5.3.0 through 5.3.5, and 5.4.0. The vulnerability was published on April 22, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 4.4–4.9 (Medium), depending on the scoring source (GitHub Advisory, Red Hat Bugzilla).
The root cause is a missing consistency check during RPZ (Response Policy Zone) transfer processing, classified as CWE-476 (NULL Pointer Dereference). When a malicious authoritative nameserver sends a crafted RPZ response, the Recursor fails to validate a pointer before dereferencing it, causing a crash. Exploitation requires the attacker to control or compromise an authoritative nameserver that the Recursor is configured to query for RPZ data, placing the attack vector as network-based but requiring high privileges (control over an authoritative server). No public proof-of-concept code has been identified (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation causes the PowerDNS Recursor process to crash, resulting in a denial of service and making DNS resolution unavailable to all clients relying on the affected instance. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. Organizations depending on the affected Recursor for DNS resolution could experience significant service disruption until the process is restarted or patched (GitHub Advisory, PowerDNS Blog).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to control an authoritative nameserver that the target Recursor queries for RPZ data, which significantly limits the attack surface (GitHub Advisory).
pdns_recursor process; core dump files generated in the Recursor working directory.PowerDNS has released patched versions addressing this vulnerability: upgrade to 5.2.9 or later for the 5.2.x branch, 5.3.6 or later for the 5.3.x branch, and 5.4.1 or later for the 5.4.x branch. As a workaround, administrators should restrict RPZ feeds to only trusted, verified authoritative nameservers and implement network segmentation to limit exposure from untrusted nameservers. Monitoring the Recursor process for unexpected crashes can help detect exploitation attempts until patching is complete (PowerDNS Blog, GitHub Advisory).
PowerDNS published a security advisory and blog post on April 22, 2026, coordinating disclosure with the release of patched versions. Red Hat tracked the issue via Bugzilla and their security advisory portal. The vulnerability was also noted in the oss-security mailing list and picked up by Linux distribution security trackers, including a Debian DSA for pdns-recursor. Community reaction has been measured given the medium severity and limited exploitability (PowerDNS Blog, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."