Description
An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Wildcard record masking
Action: Patch
AI Analysis

Impact

During zone processing, the checkwildcard() function may incorrectly accept an out‑of‑zone NSEC record as proof that no wildcard domain exists. The flaw allows an attacker who controls the same or a higher level zone to inject such a record, thereby masking the presence of a legitimate wildcard record. This can affect DNS resolution for sub‑domains and undermine security controls that rely on wildcard entries.

Affected Systems

The vulnerability affects ISC BIND 9, specifically versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and the corresponding -S1 builds (9.11.3‑S1 through 9.18.50‑S1 and 9.20.9‑S1 through 9.20.27‑S1).

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Exploitation would require an attacker to supply a suitable NSEC record in a zone they control or influence, and the named resolver would then ignore the wildcard. Therefore the attack vector is inferred to be a controlled DNS zone rather than a remote network attack. Organizations should treat this as a moderate risk until the solution is applied.

Generated by OpenCVE AI on September 18, 2026 at 00:18 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade the named package to a patched release such as BIND 9.20.29, 9.21.26, or 9.20.29‑S1.
  • Enable DNSSEC validation so that out‑of‑zone NSEC records are rejected during resolution.
  • Review and restrict zone delegation to trusted authoritative servers to reduce the chance of injected NSEC records.

Generated by OpenCVE AI on September 18, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof
First Time appeared Isc
Isc bind
Weaknesses CWE-345
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T18:44:20.015Z

Reserved: 2026-08-15T14:30:38.165Z

Link: CVE-2026-19941

cve-icon Vulnrichment

Updated: 2026-09-17T18:44:11.791Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:05.160

Modified: 2026-09-17T19:16:42.200

Link: CVE-2026-19941

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T13:52:49Z

Links: CVE-2026-19941 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-346

    Origin Validation Error