An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-powerdns-2026-03.html