Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

BIND 9 — Vulnerabilities & Security Advisories 83

All 83 CVE vulnerabilities found in BIND 9, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting the ISC BIND 9 server. It collects reported defects spanning multiple years, covering critical issues such as buffer overflows, authentication bypasses, and denial-of-service triggers that impact DNS infrastructure. Readers can use this resource to track the vendor's advisory history, understand common weakness classes like memory corruption and input validation flaws, and review the product’s vulnerability history for compliance and patching purposes. The data is curated from public sources, providing a centralized view of risks without requiring cross-referencing multiple security databases.

Vendor: ISC

CVE ID Title CVSS Severity Published
CVE-2026-77119 NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets CWE-346 5.9 Medium 2026-09-16
CVE-2026-75029 Message parser retains every identical singleton RDATA, enabling wire-to-work amplification CWE-405 5.3 Medium 2026-09-16
CVE-2026-19668 Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching CWE-407 5.3 Medium 2026-09-16
CVE-2026-19033 Unauthenticated IXFR deltas are applied to the live zone before TSIG verification CWE-349 6.5 Medium 2026-09-16
CVE-2026-80274 Validating resolver can abort while caching a mismatched NOQNAME proof CWE-617 7.5 High 2026-09-16
CVE-2026-76163 named aborts on a TKEY query when the user configuration has no global options statement CWE-617 7.5 High 2026-09-16
CVE-2026-19666 Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path CWE-416 7.5 High 2026-09-16
CVE-2026-81563 SVCB AliasMode additional-data error leaks qpcache references CWE-401 7.5 High 2026-09-16
CVE-2026-78301 Out-of-zone database nodes can become authoritative zone cuts CWE-349 5.8 Medium 2026-09-16
CVE-2026-77692 Unauthenticated remote crash of named via a single DoH SIG(0) request CWE-476 7.5 High 2026-09-16
CVE-2026-19941 checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof CWE-345 5.9 Medium 2026-09-16
CVE-2026-19662 qpcache NOQNAME proof use-after-free crashes recursive resolver CWE-416 5.9 Medium 2026-09-16
CVE-2026-19667 Remote assertion failure via 16-bit length truncation in `dns_ncache_add()` CWE-197 7.5 High 2026-09-16
CVE-2026-81736 Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees CWE-1050 7.5 High 2026-09-16
CVE-2026-13321 DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field CWE-346 8.6 High 2026-07-22
CVE-2026-13204 Unexpected exit in certain situations with NSEC and NSEC3 both present CWE-617 7.5 High 2026-07-22
CVE-2026-12617 Record ordering based unexpected exit with CNAME or DNAME CWE-617 7.5 High 2026-07-22
CVE-2026-11721 Cache poisoning possible with label count discrepancy, RRSIG, and wildcards CWE-1284 7.5 High 2026-07-22
CVE-2026-11622 Potential memory usage beyond configured limits CWE-770 7.5 High 2026-07-22
CVE-2026-11605 Unnecessary validation of DNSSEC signed records CWE-408 7.5 High 2026-07-22
CVE-2026-11331 Potential wildcard CNAME RPZ policy bypass CWE-790 7.5 High 2026-07-22
CVE-2026-10822 Key Record using PRIVATEDNS algorithm may lead to unexpected exit CWE-617 6.5 Medium 2026-07-22
CVE-2026-10723 Incorrect acceptance of NSEC3 records CWE-347 6.8 Medium 2026-07-22
CVE-2026-5950 Unbounded resend loop in BIND 9 resolver CWE-606 5.3 Medium 2026-05-20
CVE-2026-5947 SIG(0) validation during query flood may lead to undefined behavior CWE-362 7.5 High 2026-05-20
CVE-2026-5946 Invalid handling of CLASS != IN CWE-20 7.5 High 2026-05-20
CVE-2026-3593 Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation CWE-416 7.4 High 2026-05-20
CVE-2026-3592 Amplification vulnerabilities via self-pointed glue records CWE-408 5.3 Medium 2026-05-20
CVE-2026-3039 BIND 9 server memory exhaustion during GSS-API TKEY negotiation CWE-771 7.5 High 2026-05-20
CVE-2026-3591 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass CWE-562 5.4 Medium 2026-03-25

All 83 known CVE vulnerabilities affecting BIND 9 with full Chinese analysis, references, and POCs where available.