CVE-2026-5950
- EPSS 0.66%
- Veröffentlicht 20.05.2026 13:16:40
- Zuletzt bearbeitet 23.07.2026 12:10:00
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. T...
CVE-2026-3039
- EPSS 1.05%
- Veröffentlicht 20.05.2026 13:16:23
- Zuletzt bearbeitet 20.08.2026 13:18:23
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Direct...
CVE-2026-3592
- EPSS 0.41%
- Veröffentlicht 20.05.2026 13:16:23
- Zuletzt bearbeitet 24.07.2026 10:10:00
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 thr...
CVE-2026-3593
- EPSS 1.54%
- Veröffentlicht 20.05.2026 13:16:23
- Zuletzt bearbeitet 24.07.2026 10:10:00
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1...
CVE-2026-3591
- EPSS 0.36%
- Veröffentlicht 25.03.2026 13:34:14
- Zuletzt bearbeitet 21.05.2026 15:24:36
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL ...
CVE-2026-3119
- EPSS 0.58%
- Veröffentlicht 25.03.2026 13:31:54
- Zuletzt bearbeitet 21.05.2026 15:24:39
Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` co...
CVE-2026-3104
- EPSS 0.7%
- Veröffentlicht 25.03.2026 13:29:19
- Zuletzt bearbeitet 15.07.2026 02:20:58
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18...
CVE-2026-1519
- EPSS 1.6%
- Veröffentlicht 25.03.2026 13:25:19
- Zuletzt bearbeitet 03.08.2026 13:17:13
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers ma...
CVE-2025-13878
- EPSS 8.36%
- Veröffentlicht 21.01.2026 14:43:27
- Zuletzt bearbeitet 15.07.2026 02:17:16
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.
CVE-2025-40777
- EPSS 0.88%
- Veröffentlicht 16.07.2025 17:38:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, encounters a CN...