I've been suffering from this issue for a while now. While I was successfully able to work around it by disabling DNSSEC in the systemd-resolved configuration I would prefer if we could update systemd to v240 to pick up the official fixes.
Edit: v241 has been released and should be used instead as it includes patches for the recent journald vulnerabilities.