CVE-2026-1519

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*

History

21 May 2026, 15:24

Type Values Removed Values Added
CPE cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
References () https://downloads.isc.org/isc/bind9/9.18.47 - () https://downloads.isc.org/isc/bind9/9.18.47 - Patch
References () https://downloads.isc.org/isc/bind9/9.20.21 - () https://downloads.isc.org/isc/bind9/9.20.21 - Patch
References () https://downloads.isc.org/isc/bind9/9.21.20 - () https://downloads.isc.org/isc/bind9/9.21.20 - Patch
References () https://kb.isc.org/docs/cve-2026-1519 - () https://kb.isc.org/docs/cve-2026-1519 - Vendor Advisory
References () https://lists.debian.org/debian-lts-announce/2026/04/msg00008.html - () https://lists.debian.org/debian-lts-announce/2026/04/msg00008.html - Issue Tracking, Third Party Advisory
First Time Isc bind
Isc

13 Apr 2026, 10:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2026/04/msg00008.html -
Summary
  • (es) Si un resolvedor BIND está realizando validación DNSSEC y encuentra una zona creada maliciosamente, el resolvedor puede consumir CPU excesiva. Los servidores solo autoritativos generalmente no se ven afectados, aunque hay circunstancias en las que los servidores autoritativos pueden realizar consultas recursivas (ver: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). Este problema afecta a las versiones de BIND 9 9.11.0 a 9.16.50, 9.18.0 a 9.18.46, 9.20.0 a 9.20.20, 9.21.0 a 9.21.19, 9.11.3-S1 a 9.16.50-S1, 9.18.11-S1 a 9.18.46-S1, y 9.20.9-S1 a 9.20.20-S1.

25 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 14:16

Updated : 2026-05-21 15:24


NVD link : CVE-2026-1519

Mitre link : CVE-2026-1519

CVE.ORG link : CVE-2026-1519


JSON object : View

Products Affected

isc

  • bind
CWE
CWE-606

Unchecked Input for Loop Condition