CVE-2026-13321DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-13204Unexpected exit in certain situations with NSEC and NSEC3 both present Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-12617Record ordering based unexpected exit with CNAME or DNAME Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-11721Cache poisoning possible with label count discrepancy, RRSIG, and wildcards Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-11622Potential memory usage beyond configured limits Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-11605Unnecessary validation of DNSSEC signed records Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-11331Potential wildcard CNAME RPZ policy bypass Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity High CVE-2026-10822Key Record using PRIVATEDNS algorithm may lead to unexpected exit Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-10723Incorrect acceptance of NSEC3 records Exploitation status Not known exploited Fix YesPublished 07/22/2026 Severity Medium CVE-2026-5950Unbounded resend loop in BIND 9 resolver Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity Medium CVE-2026-5947SIG(0) validation during query flood may lead to undefined behavior Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity High CVE-2026-5946Invalid handling of CLASS != IN Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity High CVE-2026-3593Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity High CVE-2026-3592Amplification vulnerabilities via self-pointed glue records Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity Medium CVE-2026-3039BIND 9 server memory exhaustion during GSS-API TKEY negotiation Exploitation status Not known exploited Fix YesPublished 05/20/2026 Severity High CVE-2026-3591A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass Exploitation status Not known exploited Fix YesPublished 03/25/2026 Severity Medium CVE-2026-3119Authenticated query containing a TKEY record may cause named to terminate unexpectedly Exploitation status Not known exploited Fix YesPublished 03/25/2026 Severity Medium CVE-2026-3104Memory leak in code preparing DNSSEC proofs of non-existence Exploitation status Not known exploited Fix YesPublished 03/25/2026 Severity High CVE-2026-1519Excessive NSEC3 iterations cause high CPU load during insecure delegation validation Exploitation status Not known exploited Fix YesPublished 03/25/2026 Severity High CVE-2025-13878Malformed BRID/HHIT records can cause named to terminate unexpectedly Exploitation status Not known exploited Fix YesPublished 01/21/2026 Severity High CVE-2025-40780Cache poisoning due to weak PRNG Exploitation status Not known exploited Fix YesPublished 10/22/2025 Severity High CVE-2025-40778Cache poisoning attacks with unsolicited RRs Exploitation status Public exploit Fix YesPublished 10/22/2025 Severity High CVE-2025-8677Resource exhaustion via malformed DNSKEY handling Exploitation status Not known exploited Fix YesPublished 10/22/2025 Severity High CVE-2025-40777A possible assertion failure when 'stale-answer-client-timeout' is set to '0' Exploitation status Not known exploited Fix YesPublished 07/16/2025 Severity High CVE-2025-40776Birthday Attack against Resolvers supporting ECS Exploitation status Not known exploited Fix YesPublished 07/16/2025 Severity High CVE-2025-40775DNS message with invalid TSIG causes an assertion failure Exploitation status Not known exploited Fix YesPublished 05/21/2025 Severity High CVE-2024-12705DNS-over-HTTPS implementation suffers from multiple issues under heavy query load Exploitation status Not known exploited Fix YesPublished 01/29/2025 Severity High CVE-2024-11187Many records in the additional section cause CPU exhaustion Exploitation status Not known exploited Fix YesPublished 01/29/2025 Severity High CVE-2024-4076Assertion failure when serving both stale cache data and authoritative zone content Exploitation status Not known exploited Fix YesPublished 07/23/2024 Severity High CVE-2024-1975SIG(0) can be used to exhaust CPU resources Exploitation status Not known exploited Fix YesPublished 07/23/2024 Severity High CVE-2024-1737BIND's database will be slow if a very large number of RRs exist at the same name Exploitation status Not known exploited Fix YesPublished 07/23/2024 Severity High CVE-2024-0760A flood of DNS messages over TCP may make the server unstable Exploitation status Not known exploited Fix YesPublished 07/23/2024 Severity High CVE-2023-6516Specific recursive query patterns may lead to an out-of-memory condition Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity High CVE-2023-5680Cleaning an ECS-enabled cache may cause excessive CPU load Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity Medium CVE-2023-5679Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity High CVE-2023-5517Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity High CVE-2023-4408Parsing large DNS messages may cause excessive CPU load Exploitation status Not known exploited Fix YesPublished 02/13/2024 Severity High CVE-2023-4236named may terminate unexpectedly under high DNS-over-TLS query load Exploitation status Not confirmed Fix YesPublished 09/20/2023 Severity High CVE-2023-3341A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly Exploitation status Not known exploited Fix YesPublished 09/20/2023 Severity High CVE-2023-2911Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0 Exploitation status Not known exploited Fix YesPublished 06/21/2023 Severity High CVE-2023-2829Malformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabled Exploitation status Not known exploited Fix YesPublished 06/21/2023 Severity High CVE-2023-2828named's configured cache size limit can be significantly exceeded Exploitation status Not known exploited Fix YesPublished 06/21/2023 Severity High CVE-2022-3924named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota Exploitation status Not known exploited Fix YesPublished 01/25/2023 Severity High CVE-2022-3736named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries Exploitation status Not known exploited Fix YesPublished 01/25/2023 Severity High CVE-2022-3488named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries Exploitation status Not known exploited Fix YesPublished 01/25/2023 Severity High CVE-2022-3094An UPDATE message flood may cause named to exhaust all available memory Exploitation status Not known exploited Fix YesPublished 01/25/2023 Severity High CVE-2019-6476An error in QNAME minimization code can cause BIND to exit with an assertion failure Exploitation status Not confirmed Fix YesPublished 10/17/2019 Severity Medium CVE-2019-6475A flaw in mirror zone validity checking can allow zone data to be spoofed Exploitation status Not confirmed Fix YesPublished 10/17/2019 Severity Medium CVE-2019-6471A race condition when discarding malformed packets can cause BIND to exit with an assertion failure Exploitation status Not confirmed Fix YesPublished 10/09/2019 Severity Medium CVE-2019-6467An error in the nxdomain redirect feature can cause BIND to exit with an INSIST assertion failure in query.c Exploitation status Not confirmed Fix YesPublished 10/09/2019 Severity Medium CVE-2019-6465Zone transfer controls for writable DLZ zones were not effective Exploitation status Not confirmed Fix YesPublished 10/09/2019 Severity Medium CVE-2018-5745An assertion failure can occur if a trust anchor rolls over to an unsupported key algorithm when using managed-keys Exploitation status Not confirmed Fix YesPublished 10/09/2019 Severity Medium CVE-2018-5744A specially crafted packet can cause named to leak memory Exploitation status Not confirmed Fix YesPublished 10/09/2019 Severity High CVE-2018-5743Limiting simultaneous TCP clients was ineffective Exploitation status Not confirmed Fix YesPublished 10/09/2019 Severity High CVE-2018-5737BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other undesirable behavior, even if serve-stale is not enabled. Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity Medium CVE-2018-5740A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity High CVE-2017-3145Improper fetch cleanup sequencing in the resolver can cause named to crash Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity High CVE-2018-5741Update policies krb5-subdomain and ms-subdomain do not enforce controls promised in their documentation Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity Medium CVE-2018-5734A malformed request can trigger an assertion failure in badcache.c Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity High CVE-2016-9778An error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.c Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity High CVE-2018-5738Some versions of BIND can improperly permit recursive query service to unauthorized clients Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity Medium CVE-2017-3135Combination of DNS64 and RPZ Can Lead to Crash Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity High CVE-2017-3141Windows service and uninstall paths are not quoted when BIND is installed Exploitation status Public exploit Fix YesPublished 01/16/2019 Severity High CVE-2017-3142An error in TSIG authentication can permit unauthorized zone transfers Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity Medium CVE-2017-3140An error processing RPZ rules can cause named to loop endlessly after handling a query Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity Low CVE-2017-3136An error handling synthesized records could cause an assertion failure when using DNS64 with "break-dnssec yes;" Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity Medium CVE-2017-3138named exits with a REQUIRE assertion failure if it receives a null command string on its control channel Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity Medium CVE-2017-3143An error in TSIG authentication can permit unauthorized dynamic updates Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity High CVE-2017-3137A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME Exploitation status Not confirmed Fix YesPublished 01/16/2019 Severity High