
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13204 is a Reachable Assertion (CWE-617) vulnerability in ISC BIND 9 that causes the DNS server to exit unexpectedly during DNSSEC validation. When a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent zone, and an RRSIG signature exists for only one of these record types, BIND triggers an assertion failure and crashes. Affected versions include BIND 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1. The vulnerability was published on July 22, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, Github Advisory).
The root cause is a reachable assertion (CWE-617) in BIND's DNSSEC validation logic. When processing a proof of insecurity for a domain, BIND encounters an inconsistent state where both NSEC and NSEC3 records are present at the parent zone but only one has a corresponding RRSIG signature. This inconsistency triggers an internal assertion check that causes the named process to terminate abnormally. Exploitation requires no authentication and no user interaction — an attacker can craft or serve a malicious DNS response containing the specific NSEC/NSEC3 record combination to any BIND resolver performing DNSSEC validation (ISC KB, Red Hat Bugzilla).
Successful exploitation results in a denial of service: the BIND named process crashes, interrupting all DNS resolution services on the affected host. There is no confidentiality or integrity impact, as the vulnerability only affects availability. Organizations relying on BIND as a recursive resolver or authoritative server would experience complete loss of DNS name resolution until the service is restarted, potentially affecting all dependent services and users (Github Advisory, Red Hat Advisory).
dig to query version information or banner grabbing./var/log/named/ or syslog such as INSIST or REQUIRE assertion failures.named process without a graceful shutdown signal; repeated restarts of the BIND service if configured with a watchdog or init system.ISC has released patched versions: BIND 9.20.26 and 9.21.24 address this vulnerability. Administrators should upgrade to these versions or later as the primary remediation. As a temporary workaround, disabling DNSSEC validation (dnssec-validation no; in named.conf) will prevent the assertion from being triggered, though this reduces DNS security posture. Restricting DNS queries to trusted sources only can also reduce exposure (ISC KB, Github Advisory).
The vulnerability was disclosed on July 22, 2026, and was promptly tracked by Red Hat's Product Security team via Bugzilla, with a high severity rating assigned. The oss-security mailing list also carried a notification shortly after disclosure. No significant public researcher commentary or social media discussion has been observed beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."