
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1519 is a denial-of-service vulnerability in ISC BIND 9 where a BIND resolver performing DNSSEC validation may consume excessive CPU when it encounters a maliciously crafted DNS zone. The vulnerability was published on March 25, 2026, and affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and corresponding Supported Preview Edition (S) branches. Authoritative-only servers are generally unaffected unless they perform recursive queries. It carries a CVSS v3.1 base score of 7.5 (High) (ISC Advisory, Red Hat CVE).
The root cause is classified under CWE-606 (Unchecked Input for Loop Condition) and CWE-770 (Allocation of Resources Without Limits or Throttling). When a BIND resolver with DNSSEC validation enabled processes a specially crafted zone — specifically one involving excessive NSEC3 iterations during insecure delegation validation — it enters a computationally expensive loop without adequate bounds checking, leading to CPU exhaustion. The attack requires no authentication, no user interaction, and is exploitable remotely over the network. No preconditions beyond the resolver having DNSSEC validation enabled are required (ISC Advisory, Infinit Sec).
Successful exploitation causes the BIND resolver to consume excessive CPU resources, degrading or completely disabling DNS resolution services for all clients relying on the affected resolver. The impact is limited to availability — there is no confidentiality or integrity impact. Organizations relying on BIND for recursive DNS resolution could experience widespread DNS outages, potentially affecting all downstream services and users dependent on that resolver (ISC Advisory, Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (ISC Advisory). The EPSS score is approximately 0.036%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection plugins are available from Nessus (e.g., plugin IDs 303599, 303734, 303759) and Qualys (e.g., detection ID 288362).
named process on BIND resolver hosts without a corresponding spike in legitimate query volume./var/log/named/ or syslog) showing repeated resolution attempts for unusual or unfamiliar domain names, particularly those with DNSSEC-signed delegations from unknown authoritative servers.ISC has released patched versions: 9.18.47, 9.20.21, and 9.21.20. Operators should upgrade to the appropriate patched version for their branch as the primary remediation (ISC Advisory, ISC Downloads). As a workaround where upgrading is not immediately possible, administrators may consider disabling DNSSEC validation if it is not operationally required and acceptable within their security posture. Additionally, implementing rate limiting on DNS queries and monitoring for anomalous CPU consumption can help detect and limit the impact of exploitation attempts. Downstream vendors including Red Hat (RHSA-2026:7915, RHSA-2026:8075, RHSA-2026:8155), Ubuntu (USN-8124-1), Debian (DSA-6181-1), SUSE, Fedora, Amazon Linux, and IBM have also released patches (Red Hat Errata, Ubuntu Advisory).
The vulnerability received broad coverage across the Linux and security community, with advisories issued by multiple national cybersecurity agencies including the Canadian Centre for Cyber Security (AV26-280) and Belgium's CCB. Security news outlets including GBHackers, CyberPress, and The Hacker News covered the BIND 9 security update release. The oss-security mailing list also carried a disclosure notice. Community reaction was measured, noting the lack of public PoC and the straightforward remediation path via vendor patches (Canadian CCCS, GBHackers, The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."