« Back to list

CVE-2026-13204

Status: Undergoing AnalysisHigh (7.5)—

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Inferred by deterministic rules from the CVSS vector and CWE. Indicative only.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-13204",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-13204",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-22T18:51:59.528740Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-officer@isc.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-officer@isc.org",
      "affectedData": [
        {
          "vendor": "ISC",
          "product": "BIND 9",
          "versions": [
            {
              "status": "affected",
              "version": "9.11.0",
              "versionType": "custom",
              "lessThanOrEqual": "9.18.50"
            },
            {
              "status": "affected",
              "version": "9.20.0",
              "versionType": "custom",
              "lessThanOrEqual": "9.20.24"
            },
            {
              "status": "affected",
              "version": "9.21.0",
              "versionType": "custom",
              "lessThanOrEqual": "9.21.23"
            },
            {
              "status": "affected",
              "version": "9.11.3-S1",
              "versionType": "custom",
              "lessThanOrEqual": "9.18.50-S1"
            },
            {
              "status": "affected",
              "version": "9.20.9-S1",
              "versionType": "custom",
              "lessThanOrEqual": "9.20.24-S1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-07-22T15:16:52.080",
  "references": [
    {
      "url": "https://downloads.isc.org/isc/bind9/9.20.26",
      "source": "security-officer@isc.org"
    },
    {
      "url": "https://downloads.isc.org/isc/bind9/9.21.24",
      "source": "security-officer@isc.org"
    },
    {
      "url": "https://kb.isc.org/docs/cve-2026-13204",
      "source": "security-officer@isc.org"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-officer@isc.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-617"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.\nThis issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1."
    }
  ],
  "lastModified": "2026-07-22T20:33:11.590",
  "sourceIdentifier": "security-officer@isc.org"
}