CVE-2026-13204
published 2026-07-22CVE-2026-13204: If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.52%
42.5th percentile
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| isc | bind | — | — |
| isc | bind_9 | 9.11.0 – 9.18.50 | — |
| isc | bind_9 | 9.11.3-S1 – 9.18.50-S1 | — |
| isc | bind_9 | 9.20.0 – 9.20.24 | — |
| isc | bind_9 | 9.20.9-S1 – 9.20.24-S1 | — |
| isc | bind_9 | 9.21.0 – 9.21.23 | — |
| ubuntu | bind9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while v
ghsa_unreviewed·2026-07-22
CVE-2026-13204 [HIGH] CWE-617 If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while v
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Ubuntu
Bind vulnerability
vendor_ubuntu·2026-08-31
CVE-2026-13204 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
It was discovered that Bind incorrectly handled DNSSEC validation when a
domain was covered by both NSEC and NSEC3 records with only one type having
an RRSIG. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: bind9: Unexpected exit with NSEC and NSEC3 both present
vendor_redhat·2026-07-22·CVSS 7.5
CVE-2026-13204 [HIGH] CWE-617 bind: bind9: Unexpected exit with NSEC and NSEC3 both present
bind: bind9: Unexpected exit with NSEC and NSEC3 both present
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.
Mitigation: Upgrade to the patched release most closely related to your current version of BIND 9:
- 9.20.26
- 9.21.24
B
No detection rules found.
No public exploits indexed.
2026-07-22
Published