Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/powerdns/Recursor

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-33262 is a medium severity vulnerability in PowerDNS Recursor versions 5.2.0, 5.3.0, and 5.4.0. It involves a null pointer dereference triggered by specially crafted replies due to a missing consistency check, resulting in a denial of service condition. Cookies are disabled by default in the affected product. There is no confirmed patch or official remediation available at this time.

Join the discussion

CVE-2026-33261 is a medium severity vulnerability in PowerDNS Recursor versions 5.2.0, 5.3.0, and 5.4.0. It involves a missing support for integrity checks during a zone transition from NSEC to NSEC3, which can cause an internal inconsistency leading to a denial of service (DoS). The vulnerability does not impact confidentiality or integrity but affects availability. There is no known exploit in the wild and no official patch or remediation guidance has been provided yet.

Join the discussion
0

CVE-2026-33259 is a use-after-free vulnerability in PowerDNS Recursor versions 5.2.0, 5.3.0, and 5.4.0. It occurs when many concurrent transfers of the same Response Policy Zone (RPZ) happen, potentially leading to inconsistent RPZ data, use-after-free conditions, or a crash of the recursor. Such concurrent transfers typically only occur if the RPZ provider malfunctions. The vulnerability has a medium severity rating with a CVSS score of 5.

Join the discussion

CVE-2026-33258 is a medium severity vulnerability in PowerDNS Recursor versions 5.2.0, 5.3.0, and 5.4.0. It allows an attacker to cause excessive allocation of resources in the negative and aggressive NSEC(3) caches by publishing and querying a specially crafted DNS zone. This can lead to resource exhaustion and potential denial of service conditions. There is no confirmed patch or official remediation available at this time.

Join the discussion

CVE-2026-33256 is a medium severity vulnerability in PowerDNS Recursor versions 5.2.0, 5.3.0, and 5.4.0. It involves allocation of resources without limits or throttling in the internal web server, which is disabled by default. An attacker can send a web request that triggers unlimited memory allocation, potentially causing a denial of service. No official patch or remediation guidance is currently available.

Join the discussion

CVE-2026-33601 is a medium severity vulnerability in PowerDNS Recursor versions 5.2.0, 5.3.0, and 5.4.0. It involves a NULL pointer dereference triggered when the zoneToCache function processes a malicious authoritative server's zone data without proper consistency checks. This flaw can cause a denial of service by crashing the service. There is no confirmed patch or official remediation available at this time, and no known exploits have been reported in the wild.

Join the discussion

CVE-2026-33600 is a medium severity vulnerability in PowerDNS Recursor versions 5.2.0, 5.3.0, and 5.4.0. It involves a null pointer dereference triggered by a malicious authoritative server sending a crafted RPZ (Response Policy Zone) that lacks a necessary consistency check. This flaw can cause the PowerDNS Recursor to crash, resulting in a denial of service condition. There is no indication of confidentiality or integrity impact, and no known exploits are reported in the wild.

Join the discussion

An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.

Join the discussion

An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/powerdns/Recursor
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses