ISC / Bind 9
83 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-77119 | NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets | MEDIUM | 5.9 | Sep 16, 2026 |
| CVE-2026-75029 | Message parser retains every identical singleton RDATA, enabling wire-to-work amplification | MEDIUM | 5.3 | Sep 16, 2026 |
| CVE-2026-19668 | Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching | MEDIUM | 5.3 | Sep 16, 2026 |
| CVE-2026-19033 | Unauthenticated IXFR deltas are applied to the live zone before TSIG verification | MEDIUM | 6.5 | Sep 16, 2026 |
| CVE-2026-80274 | Validating resolver can abort while caching a mismatched NOQNAME proof | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-76163 | named aborts on a TKEY query when the user configuration has no global options statement | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-19666 | Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-81563 | SVCB AliasMode additional-data error leaks qpcache references | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-78301 | Out-of-zone database nodes can become authoritative zone cuts | MEDIUM | 5.8 | Sep 16, 2026 |
| CVE-2026-77692 | Unauthenticated remote crash of named via a single DoH SIG(0) request | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-19941 | checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof | MEDIUM | 5.9 | Sep 16, 2026 |
| CVE-2026-19662 | qpcache NOQNAME proof use-after-free crashes recursive resolver | MEDIUM | 5.9 | Sep 16, 2026 |
| CVE-2026-19667 | Remote assertion failure via 16-bit length truncation in `dns_ncache_add()` | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-81736 | Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees | HIGH | 7.5 | Sep 16, 2026 |
| CVE-2026-13321 | DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field | HIGH | 8.6 | Jul 22, 2026 |
| CVE-2026-13204 | Unexpected exit in certain situations with NSEC and NSEC3 both present | HIGH | 7.5 | Jul 22, 2026 |
| CVE-2026-12617 | Record ordering based unexpected exit with CNAME or DNAME | HIGH | 7.5 | Jul 22, 2026 |
| CVE-2026-11721 | Cache poisoning possible with label count discrepancy, RRSIG, and wildcards | HIGH | 7.5 | Jul 22, 2026 |
| CVE-2026-11622 | Potential memory usage beyond configured limits | HIGH | 7.5 | Jul 22, 2026 |
| CVE-2026-11605 | Unnecessary validation of DNSSEC signed records | HIGH | 7.5 | Jul 22, 2026 |
| CVE-2026-11331 | Potential wildcard CNAME RPZ policy bypass | HIGH | 7.5 | Jul 22, 2026 |
| CVE-2026-10822 | Key Record using PRIVATEDNS algorithm may lead to unexpected exit | MEDIUM | 6.5 | Jul 22, 2026 |
| CVE-2026-10723 | Incorrect acceptance of NSEC3 records | MEDIUM | 6.8 | Jul 22, 2026 |
| CVE-2026-5950 | Unbounded resend loop in BIND 9 resolver | MEDIUM | 5.3 | May 20, 2026 |
| CVE-2026-5947 | SIG(0) validation during query flood may lead to undefined behavior | HIGH | 7.5 | May 20, 2026 |
Showing 1 to 25 of 83 CVEs