Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

BIND 9 — Vulnerabilities & Security Advisories 69

All 69 CVE vulnerabilities found in BIND 9, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the BIND 9 DNS software developed by the Internet Systems Consortium, categorized under common weakness enumeration types. It aggregates a comprehensive collection of disclosed defects, ranging from critical remote code execution flaws to information disclosure and denial-of-service issues, covering vulnerability records from the initial public release of the software through the most recent updates. Users can leverage this resource to track vendor advisory timelines, gain a deeper understanding of specific weakness classes affecting DNS infrastructure, and review the historical vulnerability profile of this widely used product to assess long-term risk exposure. The data is organized to facilitate security research, enabling analysts to correlate reported incidents with specific version releases and configuration scenarios. By providing a centralized view of known issues, this aggregation serves as a reference for system administrators evaluating upgrade paths and for security engineers conducting threat modeling exercises. The information presented is derived from official vendor notifications, independent security research disclosures, and industry-wide monitoring efforts, ensuring a representative overview of the threat landscape relevant to BIND 9 deployments. This structured approach helps stakeholders identify patterns in defect discovery and prioritize remediation efforts based on the severity and prevalence of the identified vulnerabilities within the broader ecosystem.

Vendor: ISC

CVE IDTitleCVSSSeverityPublished
CVE-2026-13321 DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field CWE-346 8.6 High2026-07-22
CVE-2026-13204 Unexpected exit in certain situations with NSEC and NSEC3 both present CWE-617 7.5 High2026-07-22
CVE-2026-12617 Record ordering based unexpected exit with CNAME or DNAME CWE-617 7.5 High2026-07-22
CVE-2026-11721 Cache poisoning possible with label count discrepancy, RRSIG, and wildcards CWE-1284 7.5 High2026-07-22
CVE-2026-11622 Potential memory usage beyond configured limits CWE-770 7.5 High2026-07-22
CVE-2026-11605 Unnecessary validation of DNSSEC signed records CWE-408 7.5 High2026-07-22
CVE-2026-11331 Potential wildcard CNAME RPZ policy bypass CWE-790 7.5 High2026-07-22
CVE-2026-10822 Key Record using PRIVATEDNS algorithm may lead to unexpected exit CWE-617 6.5 Medium2026-07-22
CVE-2026-10723 Incorrect acceptance of NSEC3 records CWE-347 6.8 Medium2026-07-22
CVE-2026-5950 Unbounded resend loop in BIND 9 resolver CWE-606 5.3 Medium2026-05-20
CVE-2026-5947 SIG(0) validation during query flood may lead to undefined behavior CWE-362 7.5 High2026-05-20
CVE-2026-5946 Invalid handling of CLASS != IN CWE-20 7.5 High2026-05-20
CVE-2026-3593 Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation CWE-416 7.4 High2026-05-20
CVE-2026-3592 Amplification vulnerabilities via self-pointed glue records CWE-408 5.3 Medium2026-05-20
CVE-2026-3039 BIND 9 server memory exhaustion during GSS-API TKEY negotiation CWE-771 7.5 High2026-05-20
CVE-2026-3591 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass CWE-562 5.4 Medium2026-03-25
CVE-2026-3119 Authenticated query containing a TKEY record may cause named to terminate unexpectedly CWE-617 6.5 Medium2026-03-25
CVE-2026-3104 Memory leak in code preparing DNSSEC proofs of non-existence CWE-772 7.5 High2026-03-25
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation CWE-606 7.5 High2026-03-25
CVE-2025-13878 Malformed BRID/HHIT records can cause named to terminate unexpectedly CWE-617 7.5 High2026-01-21
CVE-2025-40780 Cache poisoning due to weak PRNG CWE-341 8.6 High2025-10-22
CVE-2025-40778 Cache poisoning attacks with unsolicited RRs CWE-349 8.6 High2025-10-22
CVE-2025-8677 Resource exhaustion via malformed DNSKEY handling CWE-405 7.5 High2025-10-22
CVE-2025-40777 A possible assertion failure when 'stale-answer-client-timeout' is set to '0' CWE-617 7.5 High2025-07-16
CVE-2025-40776 Birthday Attack against Resolvers supporting ECS CWE-349 8.6 High2025-07-16
CVE-2025-40775 DNS message with invalid TSIG causes an assertion failure CWE-232 7.5 High2025-05-21
CVE-2024-12705 DNS-over-HTTPS implementation suffers from multiple issues under heavy query load CWE-770 7.5 High2025-01-29
CVE-2024-11187 Many records in the additional section cause CPU exhaustion CWE-405 7.5 High2025-01-29
CVE-2024-4076 Assertion failure when serving both stale cache data and authoritative zone content 7.5 High2024-07-23
CVE-2024-1975 SIG(0) can be used to exhaust CPU resources 7.5 High2024-07-23

All 69 known CVE vulnerabilities affecting BIND 9 with full Chinese analysis, references, and POCs where available.