CVE-2026-1519
published 2026-03-25CVE-2026-1519: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.54%
72.3th percentile
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries).
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.47-1~deb12u1 (bookworm) | bind9 1:9.18.47-1~deb12u1 (bookworm) |
| isc | bind | >= 0 < 9.18.47-r0 | 9.18.47-r0 |
| isc | bind | >= 0 < 9.18.47-r0 | 9.18.47-r0 |
| isc | bind | >= 0 < 9.20.21-r0 | 9.20.21-r0 |
| isc | bind | >= 0 < 9.20.21-r0 | 9.20.21-r0 |
| isc | bind | 9.11.0 – 9.16.50 | — |
| isc | bind | >= 9.18.0 < 9.18.47 | 9.18.47 |
| isc | bind | >= 9.20.0 < 9.20.21 | 9.20.21 |
| isc | bind | >= 9.21.0 < 9.21.20 | 9.21.20 |
| isc | bind9 | >= 0 < 1:9.18.47-1~deb12u1 | 1:9.18.47-1~deb12u1 |
| isc | bind9 | >= 0 < 1:9.20.21-1~deb13u1 | 1:9.20.21-1~deb13u1 |
| isc | bind9 | >= 0 < 1:9.20.21-1 | 1:9.20.21-1 |
| isc | bind9 | >= 0 < 1:9.18.39-0ubuntu0.22.04.3 | 1:9.18.39-0ubuntu0.22.04.3 |
| isc | bind9 | >= 0 < 1:9.18.39-0ubuntu0.24.04.3 | 1:9.18.39-0ubuntu0.24.04.3 |
| isc | bind9 | >= 0 < 1:9.20.11-1ubuntu2.2 | 1:9.20.11-1ubuntu2.2 |
| isc | bind_9 | 9.11.0 – 9.16.50 | — |
| isc | bind_9 | 9.11.3-S1 – 9.16.50-S1 | — |
| isc | bind_9 | 9.18.0 – 9.18.46 | — |
| isc | bind_9 | 9.18.11-S1 – 9.18.46-S1 | — |
| isc | bind_9 | 9.20.0 – 9.20.20 | — |
| isc | bind_9 | 9.20.9-S1 – 9.20.20-S1 | — |
| isc | bind_9 | 9.21.0 – 9.21.19 | — |
| msrc | azl3_bind_9.20.18-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_bind_9.16.50-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_dhcp_4.4.3.p1-3_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
bind9 vulnerabilities
osv·2026-03-25·CVSS 7.5
CVE-2026-1519 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Samy Medjahed discovered that Bind incorrectly handled insecure
delegation validation. A remote attacker could possibly use this issue to
cause excessive NSEC3 iterations, consuming CPU resources, and leading to a
denial of service. (CVE-2026-1519)
Vitaly Simonovich discovered that Bind incorrectly handled memory when
preparing DNSSEC proofs of non-existence. A remote attacker could possibly
use this issue to cause memory consumption, leading to a denial of service.
This issue only affected Ubuntu 25.10. (CVE-2026-3104)
Vitaly Simonovich discovered that Bind incorrectly handled authenticated
queries containing TKEY records. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service. This issue
only affected Ubuntu 25.10
OSV
CVE-2026-1519: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU
osv·2026-03-25·CVSS 7.5
CVE-2026-1519 [HIGH] CVE-2026-1519: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries).
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
GHSA
GHSA-84m6-p53c-x4wp: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU
ghsa_unreviewed·2026-03-25
CVE-2026-1519 [HIGH] CWE-606 GHSA-84m6-p53c-x4wp: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries).
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
OSV
CVE-2026-1519: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU
osv·2026-03-25·CVSS 7.5
CVE-2026-1519 [HIGH] CVE-2026-1519: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
Red Hat
bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone
vendor_redhat·2026-03-25·CVSS 7.5
CVE-2026-1519 [HIGH] CWE-770 bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone
bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries).
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
A flaw was found in BIND. A remote attacker could exploit this vulnerability by sending a maliciously crafted DNSSEC-validated zone t
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2026-03-25·CVSS 7.5
CVE-2026-3591 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Samy Medjahed discovered that Bind incorrectly handled insecure
delegation validation. A remote attacker could possibly use this issue to
cause excessive NSEC3 iterations, consuming CPU resources, and leading to a
denial of service. (CVE-2026-1519)
Vitaly Simonovich discovered that Bind incorrectly handled memory when
preparing DNSSEC proofs of non-existence. A remote attacker could possibly
use this issue to cause memory consumption, leading to a denial of service.
This issue only affected Ubuntu 25.10. (CVE-2026-3104)
Vitaly Simonovich discovered that Bind incorrectly handled authenticated
queries containing TKEY records. A remote attacker could possibly use this
issue to cause Bind to crash, resulting i
Microsoft
Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
vendor_msrc·2026-03-10·CVSS 7.5
CVE-2026-1519 [HIGH] CWE-606 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Debian
CVE-2026-1519: bind9 - If a BIND resolver is performing DNSSEC validation and encounters a maliciously ...
vendor_debian·2026·CVSS 7.5
CVE-2026-1519 [HIGH] CVE-2026-1519: bind9 - If a BIND resolver is performing DNSSEC validation and encounters a maliciously ...
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
Scope: local
bookworm: resolved (fixed in 1:9.18.47-1~deb12u1)
bullseye: open
forky: resolved (fixed in 1:9.20.21-1)
sid: resolved (fixed in 1:9.20.21-1)
trixie: resolved (fixed in 1:9.20.21-1~deb13u1)
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
blogs_hackernews·2026-03-30·CVSS 9.3
[CRITICAL] ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention.
There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to.
All of it below. Let's go.
## ⚡ Threat of the Week
Citrix Flaw Comes Under Active Exploitation — A cr
Wiz
CVE-2026-1519 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-1519 [HIGH] CVE-2026-1519 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1519 :
MinimOS vulnerability analysis and mitigation
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries ).
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
MinimOS
Linux Debian
Has Publi
Bugzilla
CVE-2026-1519 bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone
bugzilla·2026-03-25·CVSS 7.5
CVE-2026-1519 [HIGH] CVE-2026-1519 bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone
CVE-2026-1519 bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries).
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:7915 h
https://downloads.isc.org/isc/bind9/9.18.47https://downloads.isc.org/isc/bind9/9.20.21https://downloads.isc.org/isc/bind9/9.21.20https://kb.isc.org/docs/cve-2026-1519https://lists.debian.org/debian-lts-announce/2026/04/msg00008.htmlhttps://access.redhat.com/errata/RHSA-2026:11371https://access.redhat.com/errata/RHSA-2026:11372https://access.redhat.com/errata/RHSA-2026:15890https://access.redhat.com/errata/RHSA-2026:16060https://access.redhat.com/errata/RHSA-2026:16064https://access.redhat.com/errata/RHSA-2026:24500https://access.redhat.com/errata/RHSA-2026:24851https://access.redhat.com/errata/RHSA-2026:24934https://access.redhat.com/errata/RHSA-2026:25083https://access.redhat.com/errata/RHSA-2026:25171https://access.redhat.com/errata/RHSA-2026:25214https://access.redhat.com/errata/RHSA-2026:29110https://access.redhat.com/errata/RHSA-2026:29863https://access.redhat.com/errata/RHSA-2026:34048https://access.redhat.com/errata/RHSA-2026:36610https://access.redhat.com/errata/RHSA-2026:6935https://access.redhat.com/errata/RHSA-2026:7915https://access.redhat.com/errata/RHSA-2026:8075https://access.redhat.com/errata/RHSA-2026:8155https://access.redhat.com/errata/RHSA-2026:8312https://access.redhat.com/errata/RHSA-2026:8352https://access.redhat.com/security/cve/CVE-2026-1519https://bugzilla.redhat.com/show_bug.cgi?id=2451305https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1519.json
2026-03-25
Published