
CVE-2026-33601 If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing … https://www.cve.org/CVERecord?id=CVE-2026-33601
Post summary
The statement reveals a null pointer dereference vulnerability in the zoneToCache function when interacting with a malicious DNS server, but provides no PoC, exploit, patch, or evidence of active exploitation.
