CVE-2026-1519
CVSS 7.5 HIGH: if a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. EPSS 2% (73rd percentile). Microsoft patch: CBL-Mariner Releases.
Vulnerabilities & Exploits
ISC released BIND 9 updates that fix four vulnerabilities affecting resolvers. Two high-severity vulnerabilities can trigger unbounded memory growth or high CPU during DNSSEC processing, potentially causing denial-of-service on resolvers.
1 source · Mar 26
CVSS 7.5 HIGH: if a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. EPSS 2% (73rd percentile). Microsoft patch: CBL-Mariner Releases.
CVSS 7.5 HIGH: a specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This… EPSS 0.7% (48th percentile). Microsoft patch: CBL-Mariner Releases.
CVSS 6.5 MEDIUM: under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. EPSS 0.6% (43rd percentile), up from 0.02%. Microsoft patch: CBL-Mariner Releases.
CVSS 5.4 MEDIUM: a use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). EPSS 0.4% (28th percentile). Microsoft patch: CBL-Mariner Releases.
SecurityWeek
BIND Updates Patch High-Severity Vulnerabilities
Specially crafted domains could be used to cause out-of-memory conditions, leading to memory leaks in the BIND resolvers.
originalPart of the PlainSec briefing for 2026-03-26
Every edition of this story: BIND Updates Patch Two High-Severity DNSSEC DoS Flaws