openwrt ▾
›
openwrt-25.12 ▾
›
vulnerability
›
CVE-2026-33259
Component Overview
Vulnerability Overview
Name
CVE-2026-33259
Source
NVD (
link
)
Debian (
link
)
Description
Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.
CWEs
CWE-416
Published Date
Apr 22, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-03.html
Broken Link
Analysis
#
Affected Component
Analysis
pdns-recursor
Exploitable
Vulnerability Ratings
#
5
CVSSv31
NaN
other
Others affected component
#
Name
Project
Project Version
Version
Status
pdns-recursor
openwrt
master
5.2.5-r1
Exploitable