Unauthenticated DoS in ISC BIND 9 via crafted SIG(0) DNS-over-HTTPS requests
ISC BIND 9 contains a NULL pointer dereference (CWE-476) that causes the `named` daemon to abort when it receives a DNS-over-HTTPS request carrying a cryptographically invalid SIG(0) record followed by a premature close of the transport connection. An unauthenticated remote attacker can trigger the crash repeatedly, achieving a denial of service with no confidentiality or integrity impact (CVSS availability-only). Only deployments running affected 9.20.x, 9.21.x, or 9.20.x-S1 versions with DoH listeners configured are exposed; servers without DoH endpoints enabled are not vulnerable. No public proof-of-concept exists, the flaw is not in the CISA KEV catalog, and no exploitation in the wild has been reported.
· Internet Systems Consortium (ISC) BIND 9 9.20.0 through 9.20.27 · Internet Systems Consortium (ISC) BIND 9 9.21.0 through 9.21.25large
Unauthenticated DoS in ISC BIND named via crafted 65536-byte negative DNS answers
CVE-2026-19667 is a numeric type conversion error (CWE-197) in ISC BIND's `named` resolver: when an authoritative server returns a negative answer (e.g., NXDOMAIN/NODATA) that is exactly 65536 bytes long, `named` mis-handles the size and stores a 0-byte negative cache entry. When that cache entry is subsequently read to answer a client query, the `named` process aborts, taking down the resolver's DNS service. An attacker who controls an authoritative server for any domain the resolver will look up (e.g., a domain they own, with lookups induced via links or other references) can crash an unpatched recursive resolver remotely without credentials. Organizations and providers running affected BIND 9 versions as caching/recursive resolvers are affected; purely authoritative servers are not the relevant exposure. As of publication there is no known public proof-of-concept, the flaw is not listed in CISA KEV, and no exploitation has been reported.
· ISC BIND 9 (named) 9.11.0 through 9.18.50 · ISC BIND 9 (named) 9.20.0 through 9.20.27mass
Algorithmic CPU-exhaustion DoS in ISC BIND 9 resolver via cached SVCB/HTTPS records
ISC BIND 9 recursive resolvers spend disproportionate CPU time constructing a response when queried for the root of a tree of SVCB/HTTPS AliasMode records that they have already cached, creating an algorithmic-complexity denial-of-service condition (CWE-1050). An unauthenticated remote attacker can trigger it simply by sending such a query to a resolver holding a cached AliasMode tree, requiring no privileges or user interaction (CVSS AV:N/AC:L/PR:N/UI:N). The attacker's gain is denial of service: the named process wastes excessive CPU on crafted queries, degrading or halting DNS resolution for the clients that depend on that resolver. Only caching/recursive BIND 9 resolvers within the affected ranges of the 9.18, 9.20, 9.21 and supported -S1 subscription branches are affected; authoritative-only servers do not maintain this cache. No public proof-of-concept is known, the issue is not on CISA's KEV list, and no in-the-wild exploitation has been reported.
· ISC BIND 9 (open-source branches) 9.18.0 through 9.18.50 · ISC BIND 9 (open-source branches) 9.20.0 through 9.20.27mass
Use-After-Free DoS in ISC BIND 9 DNS64 Resolvers
CVE-2026-19666 is a use-after-free flaw (CWE-416) in the DNS64 processing path of ISC's BIND 9 DNS server. On a recursive resolver ('named') configured with dns64, receiving an applicable answer from an authoritative server that is malformed in a specific way causes the named process to exit unexpectedly. An unauthenticated remote attacker can therefore crash the resolver, achieving a denial of service with high availability impact but no confidentiality or integrity impact (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N). Only operators running the listed BIND 9 versions with dns64 enabled are affected; resolvers without dns64 configured are not impacted by this flaw. There is no known public proof-of-concept and the vulnerability is not on the CISA KEV list, though it was disclosed as one of fourteen BIND 9 issues by ISC.
· ISC BIND 9 (stable and development branches) 9.11.0 through 9.18.50; 9.20.0 through 9.20.27; 9.21.0 through 9.21.25 · ISC BIND 9 Stable Preview Edition (-S1) 9.11.3-S1 through 9.18.50-S1; 9.20.9-S1 through 9.20.27-S1large
Unauthenticated DoS in ISC BIND 9 via TKEY query
ISC BIND 9, the widely used open-source DNS server, contains a remotely triggerable denial-of-service flaw (CWE-617, reachable assertion). If the server's named.conf file lacks a global "options" block, an unauthenticated attacker can send a DNS query of QTYPE TKEY that causes an assertion failure and unexpected exit of the named daemon. The attacker gains only availability impact — the DNS server can be crashed and kept down by repeated queries — with no confidentiality or confidentiality/integrity effect (CVSS 7.5, AV:N/AC:L/PR:N/UI:N/C:N/I:N/A:H). Affected deployments are BIND 9.20.0 through 9.20.27, the 9.21.0 through 9.21.25 development branch, and 9.20.9-S1 through 9.20.27-S1, but only where the configuration omits a global options block. No public proof-of-concept is known, it is not in CISA KEV, and it is one of fourteen BIND 9 vulnerabilities ISC has disclosed.
· ISC BIND 9 9.20.0 through 9.20.27 · ISC BIND 9 9.21.0 through 9.21.25 (development branch)large
Memory-Leak Denial of Service in ISC BIND Resolvers via Crafted SVCB/HTTPS Records
A BIND recursive resolver that processes an SVCB or HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records fails to deallocate internal resources, leaking memory with each lookup (CWE-401). A remote, unauthenticated attacker can trigger this repeatedly, for example by pointing their own domains at crafted record chains that the resolver is asked to look up, until resource exhaustion prevents the resolver from performing any new recursive lookups. The impact is a high-severity denial of service against recursive DNS service; there is no confidentiality or integrity impact. All operators running affected BIND 9.18, 9.20, or 9.21 (including the -S1 Stable Preview editions) as resolvers are exposed, with internet-facing recursive resolvers at greatest risk. As of now there is no known exploitation in the wild, no public proof-of-concept, and the flaw is not listed in CISA's KEV catalog.
· Internet Systems Consortium (ISC) BIND 9 (recursive resolver) 9.18.0 through 9.18.50 · Internet Systems Consortium (ISC) BIND 9 (recursive resolver) 9.20.0 through 9.20.27mass
TSIG Bypass in BIND 9 IXFR Transfers Lets Unsigned Data Poison Secondary Zones
In ISC BIND 9, a secondary server that restricts zone transfers with TSIG may begin serving data from an incoming multi-message TCP IXFR before the final message carrying the TSIG signature arrives, and it never rolls back to the pre-transfer state if that signature never arrives (CWE-349, acceptance of extraneous untrusted data). An attacker who does not possess a valid TSIG key but can impersonate the zone's primary on the transfer path (e.g., via a spoofed or man-in-the-middle transfer session) can send unauthorized zone contents, which the secondary then serves to clients. The impact is loss of DNS data integrity with limited availability impact and no confidentiality impact (CVSS 6.5, network vector with high attack complexity). Any BIND 9 deployment in the affected version ranges configured as a secondary zone with TSIG-restricted transfers is affected, and the transfer must be a multi-message TCP IXFR as described by RFC 8945. No exploitation in the wild, public proof-of-concept, or CISA KEV listing is known; ISC disclosed this flaw as one of fourteen BIND 9 vulnerabilities.
· ISC BIND 9 9.11.0 through 9.18.50 · ISC BIND 9 9.20.0 through 9.20.27mass
Use-after-free denial of service in ISC BIND 9 recursive resolver (named)
CVE-2026-19662 is a use-after-free flaw (CWE-416) in ISC BIND 9's named resolver that can cause the daemon to abort, resulting in a denial of service. An attacker must operate an authoritative server hosting a DNSSEC-signed zone and induce the victim resolver to send multiple queries to it; the crash only occurs if the attacker's crafted answers arrive in a particular sequence, order, and timing, making the attack reliable but non-trivial (CVSS attack complexity is High). A successful attack yields no data theft or tampering — only a crash of the resolver process (availability impact rated High). Any organization running an affected BIND 9 version as a recursive resolver is potentially exposed, since the resolver can be steered to the attacker's authoritative server via queries from its clients. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and no in-the-wild exploitation is reported; it was disclosed by ISC as part of a batch of fourteen BIND 9 vulnerabilities.
· ISC BIND 9 (open editions) 9.11.0 through 9.18.50 and 9.20.0 through 9.20.27 · ISC BIND 9 Supported Preview Edition (-S1) 9.11.3-S1 through 9.18.50-S1 and 9.20.9-S1 through 9.20.27-S1mass
Zone-cut mishandling in ISC BIND 9 enables cache poisoning via malformed zones
ISC BIND 9's named daemon incorrectly treats an NS or DNAME node placed above a zone's origin as a zone cut, so an attacker who can insert a malformed zone into an authoritative server (for example, via zone transfer or by loading zones on a shared DNS service) can make queries within that configured zone lose authoritative status and return an out-of-zone delegation. On servers that also provide recursion, BIND then follows this locally sourced, attacker-influenced cut and caches attacker-supplied data, poisoning answers for names outside the configured zone; the condition persists for as long as the malformed zone remains in the zone database. Any deployment running an affected BIND 9 version that combines authoritative service for attacker-influenceable zones with recursion, or that accepts zone transfers from less-trusted sources, is exposed. ISC assigned it CVSS 5.8 (medium) with high attack complexity and high privileges required, reflecting these preconditions. There is no evidence of exploitation in the wild, no known public proof-of-concept, and the flaw is not listed in CISA KEV.
· ISC BIND 9 (named) 9.11.0 through 9.18.50 · ISC BIND 9 (named) 9.20.0 through 9.20.27mass
Memory Growth in ISC BIND 9 Negative Cache via Duplicate Records in Responses
ISC BIND 9 fails to deduplicate records that should appear only once in a query response, such as an SOA record: when an attacker supplies multiple copies whose RDATA is identical, each copy is appended to the in-memory RDATA set. A remote attacker controlling or spoofing a response source can repeatedly trigger this to inflate the negative cache, driving up memory usage and opening the door to further memory-based attacks. The attacker gains gradual resource exhaustion on the resolver, leading to degraded or denied availability (CWE-405, low availability impact per CVSS). Any BIND 9 deployment in the listed versions is affected, with recursive/caching resolvers that cache negative answers from untrusted zones most exposed. Exploitation status: no known exploitation, no public proof-of-concept, and not listed in CISA KEV; the flaw is one of fourteen BIND 9 issues disclosed by ISC.
· ISC BIND 9 (open source editions) 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25 · ISC BIND 9 Stable Snapshot editions (S1) 9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.27-S1mass