Vulnerability in BIND Resolver Affects ISC BIND Products
CVE-2026-13321
8.6HIGH
What is CVE-2026-13321?
The BIND DNS resolver has a security issue involving the handling of validly-signed NSEC records. In this scenario, the 'Next Domain Name' field can point to an area outside the signer's zone, potentially leading to unexpected behavior and increased risk of exploitation. This affects specific versions of BIND, prompting the need for users to check and update their systems to maintain optimal security and functionality.
Affected Version(s)
BIND 9 9.11.0 <= 9.18.50
BIND 9 9.20.0 <= 9.20.24
BIND 9 9.21.0 <= 9.21.23
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
ISC would like to thank Qifan Zhang of Palo Alto Networks for bringing this vulnerability to our attention.