Description
If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of service via excessive CPU usage
Action: Patch Immediately
AI Analysis

Impact

A resolver that has cached a tree of SVCB/HTTPS AliasMode records may spend disproportionate CPU time constructing a response when queried for the root of that tree. The result is a denial‑of‑service condition affecting DNS resolution and potentially disrupting dependent services, but it does not expose confidentiality or integrity of data. The weakness corresponds to CWE-1050 and CWE-606.

Affected Systems

The vulnerability affects ISC BIND 9 products. Versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, as well as the corresponding –S1 maintenance releases, are impacted.

Risk and Exploitability

The CVSS score of 7.5 rates this as a high‑severity availability issue, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. It is not listed in CISA’s KEV catalog. The likely attack vector is a remote DNS query against a resolver that has already cached a large SVCB/HTTPS AliasMode tree; the attacker simply issues a query for the tree root to trigger the excessive CPU consumption. No privileged access or specific network configuration is required beyond obtaining the resolver’s public DNS service. The vulnerability is therefore exploitable on any public‑facing BIND 9 instance that handles SVCB/HTTPS AliasMode records.

Generated by OpenCVE AI on September 18, 2026 at 03:17 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Resolve the CWE-1050 and CWE-606 weaknesses by upgrading to the patched BIND 9 release (9.20.29, 9.21.26, or newer) and restart the resolver.
  • If SVCB/HTTPS AliasMode is not required for your environment, disable this feature to prevent the caching of AliasMode trees, which eliminates the CWE-1050 trigger.
  • Implement query throttling or rate limiting so that repeated requests for a tree root are slowed, mitigating the impact of any potential exploit.

Generated by OpenCVE AI on September 18, 2026 at 03:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Isc bind 9
Vendors & Products Isc bind 9

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees
First Time appeared Isc
Isc bind
Weaknesses CWE-1050
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T18:46:05.159Z

Reserved: 2026-08-27T11:35:23.313Z

Link: CVE-2026-81736

cve-icon Vulnrichment

Updated: 2026-09-17T18:45:58.050Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:10.817

Modified: 2026-09-17T19:17:03.880

Link: CVE-2026-81736

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T13:44:28Z

Links: CVE-2026-81736 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:05Z

Weaknesses
  • CWE-1050

    Excessive Platform Resource Consumption within a Loop

  • CWE-606

    Unchecked Input for Loop Condition