Vulnerability index

Browse CVEs

129 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bind HIGH 7.5
CVE-2026-5946

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `…

Fix: 9.18.49 / 9.20.23+
Fix from $1,950 2026-05-20
Bind MEDIUM 5.9
CVE-2026-5947

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SI…

Fix: 9.20.23 / 9.21.22+
Fix from $1,600 2026-05-20
Bind MEDIUM 5.3
CVE-2026-5950

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated atta…

Fix: 9.18.49 / 9.20.23+
Fix from $1,600 2026-05-20
Bind CRITICAL 9.8
CVE-2026-3593

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 thr…

Fix: 9.20.23 / 9.21.22+
Fix from $2,300 2026-05-20
Bind HIGH 7.5
CVE-2026-3039

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving an…

Fix: 9.18.49 / 9.20.23+
Fix from $1,950 2026-05-20
Bind MEDIUM 5.3
CVE-2026-3592

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone…

Fix: 9.18.49 / 9.20.23+
Fix from $1,600 2026-05-20
Bind MEDIUM 6.5
CVE-2026-3119

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached …

Fix: 9.20.21 / 9.21.20+
Fix from $1,600 2026-03-25
Bind MEDIUM 5.4
CVE-2026-3591

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an…

Fix: 9.20.21 / 9.21.20+
Fix from $1,600 2026-03-25
Bind HIGH 7.5
CVE-2026-3104

A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9…

Fix: 9.20.21 / 9.21.20+
Fix from $1,950 2026-03-25
Bind HIGH 7.5
CVE-2026-1519

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-o…

Fix: 9.18.47 / 9.20.21+
Fix from $1,950 2026-03-25
Stork HIGH 8.1
CVE-2024-28872

The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the Stork agen…

Fix: 1.15.1+
Fix from $1,950 2024-07-11
Bind HIGH 7.5
CVE-2023-6516

To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods…

Fix: after 9.16.45
Fix from $1,950 2024-02-13
Bind MEDIUM 5.3
CVE-2023-5680

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name ca…

Mitigation only
Fix from $1,600 2024-02-13
Bind HIGH 7.5
CVE-2023-2829

A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`…

Fix: after 9.18.15
Fix from $1,950 2023-06-21
Bind HIGH 7.5
CVE-2022-3924EPSS 16%

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured wit…

Fix: 9.16.37 / 9.18.11+
Fix from $1,950 2023-01-26
Bind HIGH 7.5
CVE-2022-3736EPSS 49%

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the …

Fix: 9.16.37 / 9.18.11+
Fix from $1,950 2023-01-26
Bind HIGH 7.5
CVE-2022-3488EPSS 19%

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can c…

No fix yet
Fix from $1,950 2023-01-26
Bind HIGH 7.5
CVE-2022-3094EPSS 13%

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack …

Fix: 9.16.37 / 9.18.11+
Fix from $1,950 2023-01-26
Bind HIGH 8.2
CVE-2022-2881

The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.

Fix: 9.18.7 / 9.19.5+
Fix from $1,950 2022-09-21
Bind HIGH 7.5
CVE-2022-2906

An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attac…

Fix: 9.18.7 / 9.19.5+
Fix from $1,950 2022-09-21
Bind HIGH 7.5
CVE-2022-1183EPSS 6%

On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those t…

Fix: after 9.18.2
Fix from $1,950 2022-05-19
Bind HIGH 7.5
CVE-2022-0635

Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate …

Mitigation only
Fix from $1,950 2022-03-23
Bind HIGH 7.5
CVE-2022-0667

When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

No fix yet
Fix from $1,950 2022-03-22
Bind HIGH 7.5
CVE-2018-5742

While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat ver…

Fix: after 9.9.4-72
Fix from $1,950 2019-10-30
Bind HIGH 7.5
CVE-2019-6475

Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of ty…

Fix: after 9.15.4
Fix from $1,950 2019-10-17
Bind HIGH 7.5
CVE-2019-6476

A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than …

Fix: after 9.15.4
Fix from $1,950 2019-10-17
Kea MEDIUM 6.5
CVE-2019-6472

A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.…

Fix: after 1.5.0
Fix from $1,600 2019-10-16
Kea MEDIUM 6.5
CVE-2019-6474

A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are reje…

Fix: after 1.5.0
Fix from $1,600 2019-10-16
Bind HIGH 7.5
CVE-2019-6469

An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response …

Mitigation only
Fix from $1,950 2019-10-09
Bind HIGH 7.5
CVE-2019-6467EPSS 5%

A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect i…

Fix: after 9.13.7
Fix from $1,950 2019-10-09