https://seclists.org/oss-sec/2026/q1/385: ISC has disclosed four vulnerabilities in BIND 9 (CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591)
Published Mar 25, 2026
·Updated
Affected Software
1 affected component
Internet Systems Consortium BIND 9<9.18.47, <9.20.21, <9.21.20
Frequently Asked Questions
1
What is the severity of CVE-2026-1519?
CVE-2026-1519 has been rated as a high severity vulnerability due to its potential to cause excessive CPU load during DNS operations.
2
How do I fix CVE-2026-1519?
To fix CVE-2026-1519, update your BIND 9 software to the latest patched version provided by Internet Systems Consortium.
3
What issues are caused by CVE-2026-3104?
CVE-2026-3104 can lead to a memory leak in the BIND 9 DNS server, which can degrade performance over time.
4
How do I remediate CVE-2026-3104?
Remediation for CVE-2026-3104 involves updating to a fixed version of BIND 9 that addresses the memory leak.
5
Are there any workarounds for CVE-2026-3591?
While the best option is to update BIND 9, temporary mitigations include reducing the amount of traffic processed by the DNS server.