Data Exposure Risk in BIND 9 by Internet Systems Consortium
CVE-2026-19033
6.5MEDIUM
What is CVE-2026-19033?
This vulnerability in BIND 9 allows an unauthorized entity to potentially access zone data during a multi-message TCP IXFR transfer, as named may serve this data prior to receiving the final TSIG signature. In cases where the TSIG is invalid or missing, BIND does not revert to the previous state, creating a significant risk for data exposure and unauthorized server content sharing.
Affected Version(s)
BIND 9 9.11.0 <= 9.18.50
BIND 9 9.20.0 <= 9.20.27
BIND 9 9.21.0 <= 9.21.25