NSEC3 Acceptance Vulnerability in BIND DNS Software by ISC
CVE-2026-77119
5.9MEDIUM
What is CVE-2026-77119?
A vulnerability exists in BIND DNS software that allows a validly signed NSEC3 from an unrelated sibling zone to be accepted as an insecurity proof. This can potentially downgrade a secure delegation, leading to the acceptance of a forged unsigned answer, which compromises DNS integrity and security.
Affected Version(s)
BIND 9 9.11.0 <= 9.18.50
BIND 9 9.20.0 <= 9.20.27
BIND 9 9.21.0 <= 9.21.25