CVE-2026-13321DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity High CVE-2026-13204Unexpected exit in certain situations with NSEC and NSEC3 both present Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity High CVE-2026-12617Record ordering based unexpected exit with CNAME or DNAME Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity High CVE-2026-11721Cache poisoning possible with label count discrepancy, RRSIG, and wildcards Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity High CVE-2026-11622Potential memory usage beyond configured limits Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity High CVE-2026-11605Unnecessary validation of DNSSEC signed records Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity High CVE-2026-11331Potential wildcard CNAME RPZ policy bypass Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity High CVE-2026-10822Key Record using PRIVATEDNS algorithm may lead to unexpected exit Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity Medium CVE-2026-10723Incorrect acceptance of NSEC3 records Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/22/2026 Severity Medium CVE-2026-5950Unbounded resend loop in BIND 9 resolver Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 05/20/2026 Severity Medium CVE-2026-5947SIG(0) validation during query flood may lead to undefined behavior Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 05/20/2026 Severity High CVE-2026-5946Invalid handling of CLASS != IN Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 05/20/2026 Severity High CVE-2026-3593Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 05/20/2026 Severity High CVE-2026-3592Amplification vulnerabilities via self-pointed glue records Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 05/20/2026 Severity Medium CVE-2026-3039BIND 9 server memory exhaustion during GSS-API TKEY negotiation Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 05/20/2026 Severity High CVE-2026-3591A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 03/25/2026 Severity Medium CVE-2026-3119Authenticated query containing a TKEY record may cause named to terminate unexpectedly Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 03/25/2026 Severity Medium CVE-2026-3104Memory leak in code preparing DNSSEC proofs of non-existence Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 03/25/2026 Severity High CVE-2026-1519Excessive NSEC3 iterations cause high CPU load during insecure delegation validation Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 03/25/2026 Severity High CVE-2026-3608Stack overflow in Kea daemons Exploitation status Not known exploited Fix YesAffected product K Kea Published 03/25/2026 Severity High CVE-2025-13878Malformed BRID/HHIT records can cause named to terminate unexpectedly Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 01/21/2026 Severity High CVE-2025-11232Invalid characters cause assert Exploitation status Not known exploited Fix YesAffected product K Kea Published 10/29/2025 Severity High CVE-2025-40780Cache poisoning due to weak PRNG Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 10/22/2025 Severity High CVE-2025-40778Cache poisoning attacks with unsolicited RRs Exploitation status Public exploit Fix YesAffected product B BIND 9 Published 10/22/2025 Severity High CVE-2025-8677Resource exhaustion via malformed DNSKEY handling Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 10/22/2025 Severity High CVE-2025-8696DoS attack against the Stork UI from an unauthenticated user Exploitation status Not known exploited Fix YesAffected product S Stork Published 09/10/2025 Severity High CVE-2025-40779Kea crash upon interaction between specific client options and subnet selection Exploitation status Not known exploited Fix YesAffected product K Kea Published 08/27/2025 Severity High CVE-2025-40777A possible assertion failure when 'stale-answer-client-timeout' is set to '0' Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/16/2025 Severity High CVE-2025-40776Birthday Attack against Resolvers supporting ECS Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/16/2025 Severity High CVE-2025-32803Insecure file permissions can result in confidential information leakage Exploitation status Not known exploited Fix YesAffected product K Kea Published 05/28/2025 Severity Medium CVE-2025-32802Insecure handling of file paths allows multiple local attacks Exploitation status Not known exploited Fix YesAffected product K Kea Published 05/28/2025 Severity Medium CVE-2025-32801Loading a malicious hook library can lead to local privilege escalation Exploitation status Not known exploited Fix YesAffected product K Kea Published 05/28/2025 Severity High CVE-2025-40775DNS message with invalid TSIG causes an assertion failure Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 05/21/2025 Severity High CVE-2024-12705DNS-over-HTTPS implementation suffers from multiple issues under heavy query load Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 01/29/2025 Severity High CVE-2024-11187Many records in the additional section cause CPU exhaustion Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 01/29/2025 Severity High CVE-2024-4076Assertion failure when serving both stale cache data and authoritative zone content Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/23/2024 Severity High CVE-2024-1975SIG(0) can be used to exhaust CPU resources Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/23/2024 Severity High CVE-2024-1737BIND's database will be slow if a very large number of RRs exist at the same name Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/23/2024 Severity High CVE-2024-0760A flood of DNS messages over TCP may make the server unstable Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 07/23/2024 Severity High CVE-2024-28872Incorrect TLS certificate validation can lead to escalated privileges Exploitation status Not known exploited Fix YesAffected product S Stork Published 07/11/2024 Severity High CVE-2023-50868Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 02/14/2024 Severity High CVE-2023-50387Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 02/14/2024 Severity High CVE-2023-6516Specific recursive query patterns may lead to an out-of-memory condition Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 02/13/2024 Severity High CVE-2023-5680Cleaning an ECS-enabled cache may cause excessive CPU load Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 02/13/2024 Severity Medium CVE-2023-5679Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 02/13/2024 Severity High CVE-2023-5517Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 02/13/2024 Severity High CVE-2023-4408Parsing large DNS messages may cause excessive CPU load Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 02/13/2024 Severity High CVE-2023-4236named may terminate unexpectedly under high DNS-over-TLS query load Exploitation status Not confirmed Fix YesAffected product B BIND 9 Published 09/20/2023 Severity High CVE-2023-3341A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 09/20/2023 Severity High CVE-2023-2911Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0 Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 06/21/2023 Severity High CVE-2023-2829Malformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabled Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 06/21/2023 Severity High CVE-2023-2828named's configured cache size limit can be significantly exceeded Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 06/21/2023 Severity High CVE-2022-3924named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 01/25/2023 Severity High CVE-2022-3736named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 01/25/2023 Severity High CVE-2022-3488named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 01/25/2023 Severity High CVE-2022-3094An UPDATE message flood may cause named to exhaust all available memory Exploitation status Not known exploited Fix YesAffected product B BIND 9 Published 01/25/2023 Severity High CVE-2022-2929DHCP memory leak Exploitation status Not confirmed Fix YesAffected product I ISC DHCP Published 10/07/2022 Severity Medium CVE-2022-2928An option refcount overflow exists in dhcpd Exploitation status Not confirmed Fix YesAffected product I ISC DHCP Published 10/07/2022 Severity Medium CVE-2022-3080BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly Exploitation status Not known exploited Fix YesAffected product B BIND9 Published 09/21/2022 Severity High CVE-2022-38178Memory leaks in EdDSA DNSSEC verification code Exploitation status Not known exploited Fix YesAffected product B BIND9 Published 09/21/2022 Severity High CVE-2022-38177Memory leak in ECDSA DNSSEC verification code Exploitation status Not known exploited Fix YesAffected product B BIND9 Published 09/21/2022 Severity High CVE-2022-2906Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only) Exploitation status Not known exploited Fix YesAffected product B BIND9 Published 09/21/2022 Severity High CVE-2022-2881Buffer overread in statistics channel code Exploitation status Not known exploited Fix YesAffected product B BIND9 Published 09/21/2022 Severity Medium CVE-2022-2795Processing large delegations may severely degrade resolver performance Exploitation status Not known exploited Fix YesAffected product B BIND9 Published 09/21/2022 Severity Medium CVE-2022-1183Destroying a TLS session early causes assertion failure Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 05/19/2022 Severity High CVE-2021-25220DNS forwarders - cache poisoning vulnerability Exploitation status Not confirmed Fix YesAffected product B BIND Published 03/23/2022 Severity Medium CVE-2022-0635Exploitation status Not confirmed Fix YesAffected product B BIND Published 03/23/2022 Severity High CVE-2022-0396DoS from specifically crafted TCP packets Exploitation status Not confirmed Fix YesAffected product B BIND Published 03/23/2022 Severity Medium CVE-2022-0667Assertion failure on delayed DS lookup Exploitation status Not confirmed Fix YesAffected product B BIND Published 03/22/2022 Severity High CVE-2021-25219Lame cache can be abused to severely degrade resolver performance Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 10/27/2021 Severity Medium CVE-2021-25218A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 08/18/2021 Severity High CVE-2021-25217A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient Exploitation status Not confirmed Fix YesAffected product I ISC DHCP Published 05/26/2021 Severity High CVE-2021-25216A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 04/29/2021 Severity High CVE-2021-25215An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 04/29/2021 Severity High CVE-2021-25214A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 04/29/2021 Severity Medium CVE-2020-8625A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 02/17/2021 Severity High CVE-2020-8624update-policy rules of type "subdomain" are enforced incorrectly Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 08/21/2020 Severity Medium CVE-2020-8623A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 08/21/2020 Severity High CVE-2020-8622A truncated TSIG response can lead to an assertion failure Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 08/21/2020 Severity Medium CVE-2020-8621Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 08/21/2020 Severity High CVE-2020-8620Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 08/21/2020 Severity High CVE-2020-8619A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 06/17/2020 Severity Medium CVE-2020-8618A buffer boundary check assertion in rdataset.c can fail incorrectly during zone transfer Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 06/17/2020 Severity Medium CVE-2020-8617A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 05/19/2020 Severity High CVE-2020-8616BIND does not sufficiently limit the number of fetches performed when processing referrals Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 05/19/2020 Severity High CVE-2019-6477TCP-pipelined queries can bypass tcp-clients limit Exploitation status Not confirmed Fix YesAffected product B BIND9 Published 11/26/2019 Severity High CVE-2013-5661Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 11/05/2019 Severity Unknown CVE-2019-6470dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries Exploitation status Not confirmed Fix Not confirmed Affected product D dhcpd Published 11/01/2019 Severity Medium CVE-2018-5742An oversight while backporting a feature leads to an assertion failure in buffer.c:420 Exploitation status Not confirmed Fix Not confirmed Affected product B BIND9 Published 10/30/2019 Severity Medium CVE-2019-6476An error in QNAME minimization code can cause BIND to exit with an assertion failure Exploitation status Not confirmed Fix YesAffected product B BIND 9 Published 10/17/2019 Severity Medium CVE-2019-6475A flaw in mirror zone validity checking can allow zone data to be spoofed Exploitation status Not confirmed Fix YesAffected product B BIND 9 Published 10/17/2019 Severity Medium CVE-2019-6474A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate Exploitation status Not confirmed Fix YesAffected product K Kea Published 10/16/2019 Severity Medium CVE-2019-6473A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate Exploitation status Not confirmed Fix YesAffected product K Kea Published 10/16/2019 Severity Medium CVE-2019-6472A packet containing a malformed DUID can cause the kea-dhcp6 server to terminate Exploitation status Not confirmed Fix YesAffected product K Kea Published 10/16/2019 Severity Medium CVE-2019-6471A race condition when discarding malformed packets can cause BIND to exit with an assertion failure Exploitation status Not confirmed Fix YesAffected product B BIND 9 Published 10/09/2019 Severity Medium CVE-2019-6469BIND Supported Preview Edition can exit with an assertion failure if ECS is in use Exploitation status Not confirmed Fix YesAffected product B BIND 9 Supported Preview Edition Published 10/09/2019 Severity Medium CVE-2019-6468BIND Supported Preview Edition can exit with an assertion failure if nxdomain-redirect is used Exploitation status Not confirmed Fix YesAffected product B BIND 9 Supported Preview Edition Published 10/09/2019 Severity Medium CVE-2019-6467An error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion failure in query.c Exploitation status Not confirmed Fix YesAffected product B BIND 9 Published 10/09/2019 Severity Medium CVE-2019-6465Zone transfer controls for writable DLZ zones were not effective Exploitation status Not confirmed Fix YesAffected product B BIND 9 Published 10/09/2019 Severity Medium CVE-2018-5745An assertion failure can occur if a trust anchor rolls over to an unsupported key algorithm when using managed-keys Exploitation status Not confirmed Fix YesAffected product B BIND 9 Published 10/09/2019 Severity Medium