PT-2026-34323 · Nlnet+1 · Unbound+1

·

CVE-2026-33259

·

Published

2026-04-22

·

Updated

2026-04-23

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Unbound (affected versions not specified)
Description Concurrent transfers of the same Response Policy Zone (RPZ) can result in inconsistent RPZ data, use after free (a memory corruption issue where a program continues to use a pointer after it has been freed), and/or a crash of the recursor. This scenario typically occurs when an RPZ provider is malfunctioning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33259

Affected Products

Powerdns Recursor
Unbound