CVE-2026-3104
published 2026-03-25CVE-2026-3104: A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.70%
49.1th percentile
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.20.21-1 (forky) | bind9 1:9.20.21-1 (forky) |
| isc | bind | >= 0 < 9.20.21-r0 | 9.20.21-r0 |
| isc | bind | >= 0 < 9.20.21-r0 | 9.20.21-r0 |
| isc | bind | >= 9.20.0 < 9.20.21 | 9.20.21 |
| isc | bind | >= 9.21.0 < 9.21.20 | 9.21.20 |
| isc | bind9 | >= 0 < 1:9.20.21-1~deb13u1 | 1:9.20.21-1~deb13u1 |
| isc | bind9 | >= 0 < 1:9.20.21-1 | 1:9.20.21-1 |
| isc | bind9 | >= 0 < 1:9.18.39-0ubuntu0.22.04.3 | 1:9.18.39-0ubuntu0.22.04.3 |
| isc | bind9 | >= 0 < 1:9.18.39-0ubuntu0.24.04.3 | 1:9.18.39-0ubuntu0.24.04.3 |
| isc | bind9 | >= 0 < 1:9.20.11-1ubuntu2.2 | 1:9.20.11-1ubuntu2.2 |
| isc | bind_9 | 9.20.0 – 9.20.20 | — |
| isc | bind_9 | 9.20.9-S1 – 9.20.20-S1 | — |
| isc | bind_9 | 9.21.0 – 9.21.19 | — |
| msrc | azl3_bind_9.20.18-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-3104: A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain
osv·2026-03-25·CVSS 7.5
CVE-2026-3104 [HIGH] CVE-2026-3104: A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
OSV
bind9 vulnerabilities
osv·2026-03-25·CVSS 7.5
CVE-2026-1519 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Samy Medjahed discovered that Bind incorrectly handled insecure
delegation validation. A remote attacker could possibly use this issue to
cause excessive NSEC3 iterations, consuming CPU resources, and leading to a
denial of service. (CVE-2026-1519)
Vitaly Simonovich discovered that Bind incorrectly handled memory when
preparing DNSSEC proofs of non-existence. A remote attacker could possibly
use this issue to cause memory consumption, leading to a denial of service.
This issue only affected Ubuntu 25.10. (CVE-2026-3104)
Vitaly Simonovich discovered that Bind incorrectly handled authenticated
queries containing TKEY records. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service. This issue
only affected Ubuntu 25.10
OSV
CVE-2026-3104: A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain
osv·2026-03-25·CVSS 7.5
CVE-2026-3104 [HIGH] CVE-2026-3104: A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
GHSA
GHSA-vwv5-298p-pw28: A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain
ghsa_unreviewed·2026-03-25
CVE-2026-3104 [HIGH] CWE-772 GHSA-vwv5-298p-pw28: A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Red Hat
bind: BIND: Denial of Service via specially crafted domain query causing a memory leak
vendor_redhat·2026-03-25·CVSS 7.5
CVE-2026-3104 [HIGH] CWE-772 bind: BIND: Denial of Service via specially crafted domain query causing a memory leak
bind: BIND: Denial of Service via specially crafted domain query causing a memory leak
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
A flaw was found in the BIND resolver. A remote attacker can exploit this vulnerability by querying a specially crafted domain, which causes a memory leak. This memory leak can lead to a Denial of Service (DoS) condition, making the BIND resolver unavailable to legitimate users.
Statement: This is an Important denial of service flaw in BIND 9. A remote attacker can trigger a memory leak
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2026-03-25·CVSS 7.5
CVE-2026-3591 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Samy Medjahed discovered that Bind incorrectly handled insecure
delegation validation. A remote attacker could possibly use this issue to
cause excessive NSEC3 iterations, consuming CPU resources, and leading to a
denial of service. (CVE-2026-1519)
Vitaly Simonovich discovered that Bind incorrectly handled memory when
preparing DNSSEC proofs of non-existence. A remote attacker could possibly
use this issue to cause memory consumption, leading to a denial of service.
This issue only affected Ubuntu 25.10. (CVE-2026-3104)
Vitaly Simonovich discovered that Bind incorrectly handled authenticated
queries containing TKEY records. A remote attacker could possibly use this
issue to cause Bind to crash, resulting i
Microsoft
Memory leak in code preparing DNSSEC proofs of non-existence
vendor_msrc·2026-03-10·CVSS 7.5
CVE-2026-3104 [HIGH] CWE-772 Memory leak in code preparing DNSSEC proofs of non-existence
Memory leak in code preparing DNSSEC proofs of non-existence
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Debian
CVE-2026-3104: bind9 - A specially crafted domain can be used to cause a memory leak in a BIND resolver...
vendor_debian·2026·CVSS 7.5
CVE-2026-3104 [HIGH] CVE-2026-3104: bind9 - A specially crafted domain can be used to cause a memory leak in a BIND resolver...
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:9.20.21-1)
sid: resolved (fixed in 1:9.20.21-1)
trixie: resolved (fixed in 1:9.20.21-1~deb13u1)
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
blogs_hackernews·2026-03-30·CVSS 9.3
[CRITICAL] ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention.
There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to.
All of it below. Let's go.
## ⚡ Threat of the Week
Citrix Flaw Comes Under Active Exploitation — A cr
Wiz
CVE-2026-3104 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-3104 [HIGH] CVE-2026-3104 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3104 :
MinimOS vulnerability analysis and mitigation
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
MinimOS
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
bind9-next-libs
bind
Sources
NVD
Alpine 3.22, 3.23, edge
https://downloads.isc.org/isc/bind9/9.20.21https://downloads.isc.org/isc/bind9/9.21.20https://kb.isc.org/docs/cve-2026-3104https://access.redhat.com/errata/RHSA-2026:6935https://access.redhat.com/security/cve/CVE-2026-3104https://bugzilla.redhat.com/show_bug.cgi?id=2451310https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3104.json
2026-03-25
Published