PT-2026-34323 · Nlnet+1 · Unbound+1

Haruto Kimura

·

Published

2026-04-22

·

Updated

2026-04-23

·

CVE-2026-33259

CVSS v3.1

5.0

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Unbound (affected versions not specified)
Description Concurrent transfers of the same Response Policy Zone (RPZ) can result in inconsistent RPZ data, use after free (a memory corruption issue where a program continues to use a pointer after it has been freed), and/or a crash of the recursor. This scenario typically occurs when an RPZ provider is malfunctioning.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-33259

Affected Products

Powerdns Recursor
Unbound