CVE-2026-3591
published 2026-03-25CVE-2026-3591: A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker…
PriorityP434medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.36%
28.6th percentile
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.20.21-1 (forky) | bind9 1:9.20.21-1 (forky) |
| isc | bind | >= 0 < 9.20.21-r0 | 9.20.21-r0 |
| isc | bind | >= 0 < 9.20.21-r0 | 9.20.21-r0 |
| isc | bind | >= 9.20.0 < 9.20.21 | 9.20.21 |
| isc | bind | >= 9.21.0 < 9.21.20 | 9.21.20 |
| isc | bind9 | >= 0 < 1:9.20.21-1~deb13u1 | 1:9.20.21-1~deb13u1 |
| isc | bind9 | >= 0 < 1:9.20.21-1 | 1:9.20.21-1 |
| isc | bind9 | >= 0 < 1:9.18.39-0ubuntu0.22.04.3 | 1:9.18.39-0ubuntu0.22.04.3 |
| isc | bind9 | >= 0 < 1:9.18.39-0ubuntu0.24.04.3 | 1:9.18.39-0ubuntu0.24.04.3 |
| isc | bind9 | >= 0 < 1:9.20.11-1ubuntu2.2 | 1:9.20.11-1ubuntu2.2 |
| isc | bind_9 | 9.20.0 – 9.20.20 | — |
| isc | bind_9 | 9.20.9-S1 – 9.20.20-S1 | — |
| isc | bind_9 | 9.21.0 – 9.21.19 | — |
| msrc | azl3_bind_9.20.18-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.4LOW
vendor_msrc5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
bind9 vulnerabilities
osv·2026-03-25·CVSS 7.5
CVE-2026-1519 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Samy Medjahed discovered that Bind incorrectly handled insecure
delegation validation. A remote attacker could possibly use this issue to
cause excessive NSEC3 iterations, consuming CPU resources, and leading to a
denial of service. (CVE-2026-1519)
Vitaly Simonovich discovered that Bind incorrectly handled memory when
preparing DNSSEC proofs of non-existence. A remote attacker could possibly
use this issue to cause memory consumption, leading to a denial of service.
This issue only affected Ubuntu 25.10. (CVE-2026-3104)
Vitaly Simonovich discovered that Bind incorrectly handled authenticated
queries containing TKEY records. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service. This issue
only affected Ubuntu 25.10
OSV
CVE-2026-3591: A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0)
osv·2026-03-25·CVSS 5.4
CVE-2026-3591 [MEDIUM] CVE-2026-3591: A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0)
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
GHSA
GHSA-5fv2-2p94-9gh7: A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0)
ghsa_unreviewed·2026-03-25
CVE-2026-3591 [MEDIUM] CWE-305 GHSA-5fv2-2p94-9gh7: A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0)
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
OSV
CVE-2026-3591: A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0)
osv·2026-03-25·CVSS 5.4
CVE-2026-3591 [MEDIUM] CVE-2026-3591: A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0)
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Red Hat
bind: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling
vendor_redhat·2026-03-25·CVSS 5.4
CVE-2026-3591 [MEDIUM] CWE-825 bind: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling
bind: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
A flaw was found in BIND, specifically in the named server's handling of DNS queries signed with SIG(0). A remote attacker could explo
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2026-03-25·CVSS 7.5
CVE-2026-3591 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Samy Medjahed discovered that Bind incorrectly handled insecure
delegation validation. A remote attacker could possibly use this issue to
cause excessive NSEC3 iterations, consuming CPU resources, and leading to a
denial of service. (CVE-2026-1519)
Vitaly Simonovich discovered that Bind incorrectly handled memory when
preparing DNSSEC proofs of non-existence. A remote attacker could possibly
use this issue to cause memory consumption, leading to a denial of service.
This issue only affected Ubuntu 25.10. (CVE-2026-3104)
Vitaly Simonovich discovered that Bind incorrectly handled authenticated
queries containing TKEY records. A remote attacker could possibly use this
issue to cause Bind to crash, resulting i
Microsoft
A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
vendor_msrc·2026-03-10·CVSS 5.4
CVE-2026-3591 [MEDIUM] CWE-562 A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Debian
CVE-2026-3591: bind9 - A use-after-return vulnerability exists in the `named` server when handling DNS ...
vendor_debian·2026·CVSS 5.4
CVE-2026-3591 [MEDIUM] CVE-2026-3591: bind9 - A use-after-return vulnerability exists in the `named` server when handling DNS ...
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:9.20.21-1)
sid: resolved (fixed in 1:9.20.21-1)
trixie: resolved (fixed in 1:9.20.21-1~deb13u1)
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
blogs_hackernews·2026-03-30·CVSS 9.3
[CRITICAL] ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention.
There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to.
All of it below. Let's go.
## ⚡ Threat of the Week
Citrix Flaw Comes Under Active Exploitation — A cr
Wiz
CVE-2026-3591 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.6
CVE-2026-3591 [HIGH] CVE-2026-3591 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3591 :
MinimOS vulnerability analysis and mitigation
named
Source : NVD
## 5.4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
MinimOS
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
bind9.16-libs
bind9.16-license
Sources
NVD
Alpine 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 26, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Mar 26, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Mar 26, 2026
Echo Severity MEDIUM No Fix Added at: Mar 26, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 29, 2026
Red Hat 6, 7, 8, 9, 10 Seve
Bugzilla
CVE-2026-3591 bind9-next: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling [fedora-all]
bugzilla·2026-03-26·CVSS 5.4
CVE-2026-3591 [MEDIUM] CVE-2026-3591 bind9-next: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling [fedora-all]
CVE-2026-3591 bind9-next: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-bcc66a29da (bind9-next-9.21.20-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-bcc66a29da
---
FEDORA-2026-a6efefa854 (bind9-next-9.21.20-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-a6efefa854
---
FEDORA-2026-01c20fe8ca (bind9-next-9.21.20-1.fc44) has been submitted as an update to Fedora 44.
https:/
Bugzilla
CVE-2026-3591 bind: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling
bugzilla·2026-03-25·CVSS 5.4
CVE-2026-3591 [MEDIUM] CVE-2026-3591 bind: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling
CVE-2026-3591 bind: BIND: Unauthorized access due to use-after-return vulnerability in DNS query handling
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Discussion:
This bug does not affect bind component, but does affect bind9-next component in Fedora only. Bug #2440560
2026-03-25
Published