NSEC/NSEC3 Domain Validation Issue in BIND by ISC
CVE-2026-13204
7.5HIGH
What is CVE-2026-13204?
A flaw has been identified in BIND where a provably insecure domain, covered by both NSEC and NSEC3 records, may lead to unexpected termination of the BIND process. This occurs when there is an RRSIG present for only one of the record types during the validation process, resulting in an assertion failure. This vulnerability affects multiple versions of BIND 9, requiring users to upgrade to avoid potential security issues.
Affected Version(s)
BIND 9 9.11.0 <= 9.18.50
BIND 9 9.20.0 <= 9.20.24
BIND 9 9.21.0 <= 9.21.23
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
ISC would like to thank Qifan Zhang of Palo Alto Networks for bringing this vulnerability to our attention.