CVE-2026-81736: Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees
If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.21.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.29-S1
Event History
Frequently Asked Questions
What must an attacker do to trigger the CPU exhaustion?
The resolver must first have cached a tree of SVCB/HTTPS AliasMode records. An attacker can then query the root of that cached tree, causing disproportionate CPU consumption while the resolver constructs its response.
Are unauthenticated remote attackers able to exploit this?
Yes. The supplied vector indicates network access, low attack complexity, no privileges, and no user interaction are required.
Which BIND 9 release lines are affected?
Affected versions are 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.