Description
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Published: 2026-07-22
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

BIND may accept child‑zone NSEC3 records that do not correctly represent the zone’s existence, allowing an attacker to forge authenticated NXDOMAIN responses. This flaw can be used to deceive clients into believing a domain does not exist or lies elsewhere, enabling redirect or denial of service without needing direct access to the zone data. The weakness is defined by CWE‑345 (Incorrect Validation of Data) and CWE‑347 (Incorrect Logical Comparison).

Affected Systems

ISC BIND 9 is affected, specifically versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3‑S1 through 9.18.50‑S1, and 9.20.9‑S1 through 9.20.24‑S1. All deployments using these releases should be assessed for exposure.

Risk and Exploitability

The CVSS score of 6.8 classifies this as a medium‑severity issue. EPSS is reported as less than 1%, indicating a very low probability of active exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a remote attacker sending specially crafted DNS queries to a vulnerable server; successful exploitation would result in forged authenticated NXDOMAIN responses, potentially redirecting traffic or causing application failures. No workarounds are known, so mitigation relies on updating BIND to a patched release.

Generated by OpenCVE AI on August 3, 2026 at 23:36 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.26, 9.21.24, or 9.20.26-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Stop the DNS service before applying changes.
  • Download the patched release – 9.20.26, 9.21.24, or 9.20.26‑S1 – from the official ISC site and install it using the distribution’s preferred package manager or binary replacement method.
  • Restart the BIND service to load the updated binaries and verify that DNSSEC validation remains enabled.

Generated by OpenCVE AI on August 3, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4725-1 bind9 security update
Debian DSA Debian DSA DSA-6395-1 bind9 security update
History

Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 23 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Isc bind 9
Vendors & Products Isc bind 9

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Title Incorrect acceptance of NSEC3 records
First Time appeared Isc
Isc bind
Weaknesses CWE-347
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-07-22T18:47:43.659Z

Reserved: 2026-06-03T07:56:36.024Z

Link: CVE-2026-10723

cve-icon Vulnrichment

Updated: 2026-07-22T18:47:39.695Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-22T15:16:51.190

Modified: 2026-07-22T20:33:11.590

Link: CVE-2026-10723

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-22T00:00:00Z

Links: CVE-2026-10723 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:06Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-347

    Improper Verification of Cryptographic Signature