An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33262.json",
"cna_assigner": "OX"
}{
"cpe": [
"cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*",
"cpe:2.3:a:powerdns:recursor:5.4.0:*:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING"
],
"extracted_events": [
{
"introduced": "5.2.0"
},
{
"fixed": "5.2.9"
},
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.6"
},
{
"introduced": "5.4.0"
},
{
"last_affected": "5.4.0"
}
]
}"2026-07-22T03:08:55Z"
[
{
"signature_type": "Line",
"target": {
"file": "pdns/recursordist/rpzloader.cc"
},
"deprecated": false,
"source": "https://github.com/powerdns/pdns/commit/1d377042e08ae8843834f572882cf5e7933779a0",
"id": "CVE-2026-33262-95ede998",
"signature_version": "v1",
"digest": {
"line_hashes": [
"267164273993890695462681232822702173228",
"254147238750497149020354176624768531180",
"111833849558877957770686629013387565768",
"172795771022719102256161942256088786852",
"116846252582779990294504138599689757229",
"132209276398926440573610110361447772713"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "pdns/recursordist/rpzloader.cc"
},
"deprecated": false,
"source": "https://github.com/powerdns/pdns/commit/b297bb729c002bc715a362fb0dd953e581c9055b",
"id": "CVE-2026-33262-eff8fcee",
"signature_version": "v1",
"digest": {
"line_hashes": [
"267164273993890695462681232822702173228",
"254147238750497149020354176624768531180",
"111833849558877957770686629013387565768",
"172795771022719102256161942256088786852",
"116846252582779990294504138599689757229",
"132209276398926440573610110361447772713"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33262.json"