Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ISC — Vulnerabilities & Security Advisories 130

Browse all 130 CVE security advisories affecting ISC. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ISC, primarily known for its Internet Systems Consortium software including BIND DNS and DHCP servers, serves as critical infrastructure for global name resolution and network configuration. With 101 recorded CVEs, the project has historically faced diverse security challenges, ranging from remote code execution and buffer overflows to cross-site scripting and privilege escalation vulnerabilities. These flaws often stem from complex parsing logic or improper input validation within the core networking daemons. Notable incidents include critical DNS cache poisoning risks and denial-of-service vectors that have prompted urgent patches across major distributions. The high volume of vulnerabilities reflects the software’s pervasive deployment and the rigorous scrutiny applied to its codebase. While ISC maintains an active security response process, the sheer number of disclosed issues highlights the inherent complexity of maintaining foundational internet protocols. Continuous updates remain essential for administrators relying on these tools to ensure network stability and integrity against evolving threat landscapes.

Found 83 results / 130 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-77119 NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets — BIND 9 CWE-346 5.9 Medium 2026-09-16
CVE-2026-75029 Message parser retains every identical singleton RDATA, enabling wire-to-work amplification — BIND 9 CWE-405 5.3 Medium 2026-09-16
CVE-2026-19668 Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching — BIND 9 CWE-407 5.3 Medium 2026-09-16
CVE-2026-19033 Unauthenticated IXFR deltas are applied to the live zone before TSIG verification — BIND 9 CWE-349 6.5 Medium 2026-09-16
CVE-2026-80274 Validating resolver can abort while caching a mismatched NOQNAME proof — BIND 9 CWE-617 7.5 High 2026-09-16
CVE-2026-76163 named aborts on a TKEY query when the user configuration has no global options statement — BIND 9 CWE-617 7.5 High 2026-09-16
CVE-2026-19666 Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path — BIND 9 CWE-416 7.5 High 2026-09-16
CVE-2026-81563 SVCB AliasMode additional-data error leaks qpcache references — BIND 9 CWE-401 7.5 High 2026-09-16
CVE-2026-78301 Out-of-zone database nodes can become authoritative zone cuts — BIND 9 CWE-349 5.8 Medium 2026-09-16
CVE-2026-77692 Unauthenticated remote crash of named via a single DoH SIG(0) request — BIND 9 CWE-476 7.5 High 2026-09-16
CVE-2026-19941 checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof — BIND 9 CWE-345 5.9 Medium 2026-09-16
CVE-2026-19662 qpcache NOQNAME proof use-after-free crashes recursive resolver — BIND 9 CWE-416 5.9 Medium 2026-09-16
CVE-2026-19667 Remote assertion failure via 16-bit length truncation in `dns_ncache_add()` — BIND 9 CWE-197 7.5 High 2026-09-16
CVE-2026-81736 Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees — BIND 9 CWE-1050 7.5 High 2026-09-16
CVE-2026-13321 DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field — BIND 9 CWE-346 8.6 High 2026-07-22
CVE-2026-13204 Unexpected exit in certain situations with NSEC and NSEC3 both present — BIND 9 CWE-617 7.5 High 2026-07-22
CVE-2026-12617 Record ordering based unexpected exit with CNAME or DNAME — BIND 9 CWE-617 7.5 High 2026-07-22
CVE-2026-11721 Cache poisoning possible with label count discrepancy, RRSIG, and wildcards — BIND 9 CWE-1284 7.5 High 2026-07-22
CVE-2026-11622 Potential memory usage beyond configured limits — BIND 9 CWE-770 7.5 High 2026-07-22
CVE-2026-11605 Unnecessary validation of DNSSEC signed records — BIND 9 CWE-408 7.5 High 2026-07-22
CVE-2026-11331 Potential wildcard CNAME RPZ policy bypass — BIND 9 CWE-790 7.5 High 2026-07-22
CVE-2026-10822 Key Record using PRIVATEDNS algorithm may lead to unexpected exit — BIND 9 CWE-617 6.5 Medium 2026-07-22
CVE-2026-10723 Incorrect acceptance of NSEC3 records — BIND 9 CWE-347 6.8 Medium 2026-07-22
CVE-2026-5950 Unbounded resend loop in BIND 9 resolver — BIND 9 CWE-606 5.3 Medium 2026-05-20
CVE-2026-5947 SIG(0) validation during query flood may lead to undefined behavior — BIND 9 CWE-362 7.5 High 2026-05-20
CVE-2026-5946 Invalid handling of CLASS != IN — BIND 9 CWE-20 7.5 High 2026-05-20
CVE-2026-3593 Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation — BIND 9 CWE-416 7.4 High 2026-05-20
CVE-2026-3592 Amplification vulnerabilities via self-pointed glue records — BIND 9 CWE-408 5.3 Medium 2026-05-20
CVE-2026-3039 BIND 9 server memory exhaustion during GSS-API TKEY negotiation — BIND 9 CWE-771 7.5 High 2026-05-20
CVE-2026-3591 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass — BIND 9 CWE-562 5.4 Medium 2026-03-25

This page lists every published CVE security advisory associated with ISC. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.