Last updated 19 August 2026
Last updated 19 August 2026
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.
On 22 July 2026, Internet Systems Consortium disclosed nine vulnerabilities affecting our BIND 9 software:
- CVE-2026-10723: Incorrect acceptance of NSEC3 records https://kb.isc.org/docs/cve-2026-10723 - CVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit https://kb.isc.org/docs/cve-2026-10822 - CVE-2026-11331: Potential wildcard CNAME RPZ policy bypass https://kb.isc.org/docs/cve-2026-11331 - CVE-2026-11605: Unnecessary validation of DNSSEC signed records https://kb.isc.org/docs/cve-2026-11605 - CVE-2026-11622: Potential memory usage beyond configured limits https://kb.isc.org/docs/cve-2026-11622 - CVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards https://kb.isc.org/docs/cve-2026-11721 - CVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME https://kb.isc.org/docs/cve-2026-12617 - CVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present https://kb.isc.org/docs/cve-2026-13204 - CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field https://kb.isc.org/docs/cve-2026-13321
New versions of BIND 9 are available:
- https://downloads.isc.org/isc/bind9/9.20.26/ - https://downloads.isc.org/isc/bind9/9.21.24/
For more information and other release formats, consult the ISC software download page: https://www.isc.org/download/
With the public announcement of these vulnerabilities, the embargo period is ended and any updated software packages that have been prepared may be released.
-- Best regards, Michał Kępień
BIND may accept incorrect child-zone NSEC3 records as valid, allowing forged authenticated NXDOMAIN responses for sibling zones. AC:H (high complexity) keeps severity at Medium despite S:C.
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
An attacker's zone can respond with an RRSIG with fewer labels than the zone it's in, causing named to produce a wildcard name shorter than the attacker's zone — resulting in cache poisoning. Requires synth-from-dnssec yes (which IS the default).
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform validation. The increased memory usage can be orders of magnitude beyond the limit configured in the max-cache-size parameter. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software.
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
Last updated 22 May 2026
Invalid handling of CLASS != IN
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.
BIND 9 server memory exhaustion during GSS-API TKEY negotiation
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
Authenticated query containing a TKEY record may cause named to terminate unexpectedly
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
An attacker can cause named to crash by sending a request that results in a corrupt or malicious record.
- Authoritative servers are affected by this vulnerability.
- Resolvers are affected by this vulnerability.
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
Cache poisoning due to weak PRNG
Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This vulnerability affects upstream's bind9 versions bellow: 9.16.13 -> 9.16.50 9.18.0 -> 9.18.27 9.19.0 -> 9.19.24
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
A bad interaction between DNS64 and serve-stale may cause named to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
A flaw in query-handling code can cause named to exit prematurely with an assertion failure when:
- nxdomain-redirect <domain>; is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response. This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.