Skip to main content

Vendor/product archive

isc / bind CVEs

Beta · best-effort

178 CVEs tagged to isc / bind6 Critical, 90 High, 77 Medium, 5 Low, 0 Unrated.

CVE-2026-5950

Published May 20, 2026

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2026-5947

Published May 20, 2026

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to valida…

CVSS 7.5 · High
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2026-5946

Published May 20, 2026

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that…

CVSS 7.5 · High
evidence mentions
14
Buzz score
47.1
Vendor/product tagsBeta · best-effort

CVE-2026-3593

Published May 20, 2026

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 th…

CVSS 7.4 · High
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2026-3592

Published May 20, 2026

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume di…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2026-3039

Published May 20, 2026

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-const…

CVSS 7.5 · High
evidence mentions
14
Buzz score
47.1
Vendor/product tagsBeta · best-effort

CVE-2026-3591

Published Mar 25, 2026

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-3119

Published Mar 25, 2026

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a v…

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-3104

Published Mar 25, 2026

A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0…

CVSS 7.5 · High
evidence mentions
8
Buzz score
42.0
Vendor/product tagsBeta · best-effort

CVE-2026-1519

Published Mar 25, 2026

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaf…

CVSS 7.5 · High
evidence mentions
32
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2023-50868

Published Feb 14, 2024

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2023-50387

Published Feb 14, 2024

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2023-5680

Published Feb 13, 2024

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query p…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4236

Published Sep 20, 2023

A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2023-2911

Published Jun 21, 2023

If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-re…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2023-2829

Published Jun 21, 2023

A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled ca…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2023-2828

Published Jun 21, 2023

Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2022-3924

Published Jan 26, 2023

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero.…

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2022-3736

Published Jan 26, 2023

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG que…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2022-3488

Published Jan 26, 2023

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an asse…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-25 of 178 CVEsPage 1 of 8