ISC
ISC Bind: vulnerabilidades y CVE
ISC Bind tiene 224 vulnerabilidades publicadas, 41 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE224
Últimos 12 meses41
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-80274 | Alta (7.5) | 0.67% | — | 16 sept 2026 | If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it… |
| CVE-2026-77119 | Media (5.9) | 0.23% | — | 16 sept 2026 | A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0… |
| CVE-2026-76163 | Alta (7.5) | 0.67% | — | 16 sept 2026 | If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue… |
| CVE-2026-75029 | Media (5.3) | 0.71% | — | 16 sept 2026 | In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory… |
| CVE-2026-19668 | Media (5.3) | 0.47% | — | 16 sept 2026 | A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name"… |
| CVE-2026-19666 | Alta (7.5) | 0.57% | — | 16 sept 2026 | On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions… |
| CVE-2026-19033 | Media (6.5) | 0.24% | — | 16 sept 2026 | For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does… |
| CVE-2026-81736 | Alta (7.5) | 0.86% | — | 16 sept 2026 | If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9… |
| CVE-2026-81563 | Alta (7.5) | 0.67% | — | 16 sept 2026 | A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will… |
| CVE-2026-78301 | Media (5.8) | 0.22% | — | 16 sept 2026 | A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for… |
| CVE-2026-77692 | Alta (7.5) | 0.67% | — | 16 sept 2026 | An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9… |
| CVE-2026-19941 | Media (5.9) | 0.23% | — | 16 sept 2026 | An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's… |
| CVE-2026-19667 | Alta (7.5) | 0.55% | — | 16 sept 2026 | If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read,… |
| CVE-2026-19662 | Media (5.9) | 0.45% | — | 16 sept 2026 | An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the… |
| CVE-2026-13321 | Alta (8.6) | 0.22% | — | 22 jul 2026 | The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0… |
| CVE-2026-13204 | Alta (7.5) | 0.52% | — | 22 jul 2026 | If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this… |
| CVE-2026-12617 | Alta (7.5) | 0.50% | — | 22 jul 2026 | The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME… |
| CVE-2026-11721 | Alta (7.5) | 0.40% | — | 22 jul 2026 | It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that… |
| CVE-2026-11622 | Alta (7.5) | 0.54% | — | 22 jul 2026 | A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to be able to send queries faster than the resolver can perform… |
| CVE-2026-11605 | Alta (7.5) | 0.54% | — | 22 jul 2026 | The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone… |
| CVE-2026-11331 | Alta (7.5) | 0.43% | — | 22 jul 2026 | An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly… |
| CVE-2026-10822 | Media (6.5) | 0.38% | — | 22 jul 2026 | If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.).… |
| CVE-2026-10723 | Media (6.8) | 0.27% | — | 22 jul 2026 | BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24,… |
| CVE-2026-52690 | Media (5.9) | 0.43% | — | 25 jun 2026 | Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail. |
| CVE-2026-40012 | Media (5.3) | 0.45% | — | 25 jun 2026 | — |
| CVE-2026-40211 | Media (5.3) | 0.70% | — | 25 jun 2026 | An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it… |
| CVE-2026-40208 | Baja (3.7) | 0.40% | — | 25 jun 2026 | An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame. |
| CVE-2026-5950 | Media (5.3) | 0.80% | — | 20 may 2026 | An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that… |
| CVE-2026-5947 | Media (5.9) | 0.80% | — | 20 may 2026 | Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that… |
| CVE-2026-5946 | Alta (7.5) | 1.7% | — | 20 may 2026 | Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`)… |