CVE-2026-19941: checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof
An inapplicable NSEC record may be accepted by a named resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.29 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.21.26 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.29-S1
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments are BIND 9 named resolvers running versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, or 9.20.9-S1 through 9.20.27-S1.
What must an attacker be able to do?
The attacker must be at the same or an upstream level of the zone name and be able to cause an inapplicable, out-of-zone NSEC record to be considered by the resolver. The result is masking the existence of a victim wildcard record rather than disclosure or denial of service.
What is the security impact?
A vulnerable named resolver may accept the inappropriate NSEC record as proof that no wildcard exists. This can cause the resolver to treat a victim wildcard record as nonexistent, affecting integrity of DNS resolution results.