Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ISC — Vulnerabilities & Security Advisories 116

Browse all 116 CVE security advisories affecting ISC. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ISC, primarily known for its Internet Systems Consortium software including BIND DNS and DHCP servers, serves as critical infrastructure for global name resolution and network configuration. With 101 recorded CVEs, the project has historically faced diverse security challenges, ranging from remote code execution and buffer overflows to cross-site scripting and privilege escalation vulnerabilities. These flaws often stem from complex parsing logic or improper input validation within the core networking daemons. Notable incidents include critical DNS cache poisoning risks and denial-of-service vectors that have prompted urgent patches across major distributions. The high volume of vulnerabilities reflects the software’s pervasive deployment and the rigorous scrutiny applied to its codebase. While ISC maintains an active security response process, the sheer number of disclosed issues highlights the inherent complexity of maintaining foundational internet protocols. Continuous updates remain essential for administrators relying on these tools to ensure network stability and integrity against evolving threat landscapes.

CVE ID Title CVSS Severity Published
CVE-2026-13321 DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field — BIND 9 CWE-346 8.6 High 2026-07-22
CVE-2026-13204 Unexpected exit in certain situations with NSEC and NSEC3 both present — BIND 9 CWE-617 7.5 High 2026-07-22
CVE-2026-12617 Record ordering based unexpected exit with CNAME or DNAME — BIND 9 CWE-617 7.5 High 2026-07-22
CVE-2026-11721 Cache poisoning possible with label count discrepancy, RRSIG, and wildcards — BIND 9 CWE-1284 7.5 High 2026-07-22
CVE-2026-11622 Potential memory usage beyond configured limits — BIND 9 CWE-770 7.5 High 2026-07-22
CVE-2026-11605 Unnecessary validation of DNSSEC signed records — BIND 9 CWE-408 7.5 High 2026-07-22
CVE-2026-11331 Potential wildcard CNAME RPZ policy bypass — BIND 9 CWE-790 7.5 High 2026-07-22
CVE-2026-10822 Key Record using PRIVATEDNS algorithm may lead to unexpected exit — BIND 9 CWE-617 6.5 Medium 2026-07-22
CVE-2026-10723 Incorrect acceptance of NSEC3 records — BIND 9 CWE-347 6.8 Medium 2026-07-22
CVE-2026-5950 Unbounded resend loop in BIND 9 resolver — BIND 9 CWE-606 5.3 Medium 2026-05-20
CVE-2026-5947 SIG(0) validation during query flood may lead to undefined behavior — BIND 9 CWE-362 7.5 High 2026-05-20
CVE-2026-5946 Invalid handling of CLASS != IN — BIND 9 CWE-20 7.5 High 2026-05-20
CVE-2026-3593 Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation — BIND 9 CWE-416 7.4 High 2026-05-20
CVE-2026-3592 Amplification vulnerabilities via self-pointed glue records — BIND 9 CWE-408 5.3 Medium 2026-05-20
CVE-2026-3039 BIND 9 server memory exhaustion during GSS-API TKEY negotiation — BIND 9 CWE-771 7.5 High 2026-05-20
CVE-2026-3591 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass — BIND 9 CWE-562 5.4 Medium 2026-03-25
CVE-2026-3119 Authenticated query containing a TKEY record may cause named to terminate unexpectedly — BIND 9 CWE-617 6.5 Medium 2026-03-25
CVE-2026-3104 Memory leak in code preparing DNSSEC proofs of non-existence — BIND 9 CWE-772 7.5 High 2026-03-25
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation — BIND 9 CWE-606 7.5 High 2026-03-25
CVE-2026-3608 Stack overflow in Kea daemons — Kea CWE-617 7.5 High 2026-03-25
CVE-2025-13878 Malformed BRID/HHIT records can cause named to terminate unexpectedly — BIND 9 CWE-617 7.5 High 2026-01-21
CVE-2025-11232 Invalid characters cause assert — Kea CWE-823 7.5 High 2025-10-29
CVE-2025-40780 Cache poisoning due to weak PRNG — BIND 9 CWE-341 8.6 High 2025-10-22
CVE-2025-40778 Cache poisoning attacks with unsolicited RRs — BIND 9 CWE-349 8.6 High 2025-10-22
CVE-2025-8677 Resource exhaustion via malformed DNSKEY handling — BIND 9 CWE-405 7.5 High 2025-10-22
CVE-2025-8696 DoS attack against the Stork UI from an unauthenticated user — Stork CWE-789 7.5 High 2025-09-10
CVE-2025-40779 Kea crash upon interaction between specific client options and subnet selection — Kea CWE-476 7.5 High 2025-08-27
CVE-2025-40777 A possible assertion failure when 'stale-answer-client-timeout' is set to '0' — BIND 9 CWE-617 7.5 High 2025-07-16
CVE-2025-40776 Birthday Attack against Resolvers supporting ECS — BIND 9 CWE-349 8.6 High 2025-07-16
CVE-2025-32803 Insecure file permissions can result in confidential information leakage — Kea CWE-276 4.0 Medium 2025-05-28

This page lists every published CVE security advisory associated with ISC. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.