ISC BIND
19 known vulnerabilities in ISC BIND, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-80274 CVSS 7.5 high If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer…
- CVE-2026-77119 CVSS 5.9 medium A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting…
- CVE-2026-76163 CVSS 7.5 high If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which…
- CVE-2026-75029 CVSS 5.3 medium In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the…
- CVE-2026-19668 CVSS 5.3 medium A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid…
- CVE-2026-19666 CVSS 7.5 high On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the…
- CVE-2026-19033 CVSS 6.5 medium For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final…
- CVE-2026-81736 CVSS 7.5 high If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will…
- CVE-2026-81563 CVSS 7.5 high A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly…
- CVE-2026-78301 CVSS 5.8 medium A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed…
- CVE-2026-77692 CVSS 7.5 high An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and…
- CVE-2026-19941 CVSS 5.9 medium An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the…
- CVE-2026-19667 CVSS 7.5 high If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results…
- CVE-2026-19662 CVSS 5.9 medium An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries…
- CVE-2026-13321 CVSS 8.6 high The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue…
- CVE-2026-13204 CVSS 7.5 high If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these…
- CVE-2026-11721 CVSS 7.5 high It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the…
- CVE-2026-11622 CVSS 7.5 high A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage…
- CVE-2026-10723 CVSS 6.8 medium BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This…