Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-5946
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `…
Bind
9.18.49 / 9.20.23+
MEDIUM 5.9
CVE-2026-5947
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SI…
Bind
9.20.23 / 9.21.22+
MEDIUM 5.3
CVE-2026-5950
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated atta…
Bind
9.18.49 / 9.20.23+
CRITICAL 9.8
CVE-2026-3593
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 thr…
Bind
9.20.23 / 9.21.22+
HIGH 7.5
CVE-2026-3039
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving an…
Bind
9.18.49 / 9.20.23+
MEDIUM 5.3
CVE-2026-3592
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone…
Bind
9.18.49 / 9.20.23+
MEDIUM 6.5
CVE-2026-3119
Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached …
Bind
9.20.21 / 9.21.20+
MEDIUM 5.4
CVE-2026-3591
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an…
Bind
9.20.21 / 9.21.20+
HIGH 7.5
CVE-2026-3104
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.
This issue affects BIND 9 versions 9…
Bind
9.20.21 / 9.21.20+
HIGH 7.5
CVE-2026-1519
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-o…
Bind
9.18.47 / 9.20.21+
HIGH 8.1
CVE-2024-28872
The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the Stork agen…
Stork
1.15.1+
HIGH 7.5
CVE-2023-6516
To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods…
Bind
after 9.16.45
MEDIUM 5.3
CVE-2023-5680
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name ca…
Bind
Mitigation only
HIGH 7.5
CVE-2023-2829
A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`…
Bind
after 9.18.15
HIGH 7.5
CVE-2022-3924EPSS 16%
This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured wit…
Bind
9.16.37 / 9.18.11+
HIGH 7.5
CVE-2022-3736EPSS 49%
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the …
Bind
9.16.37 / 9.18.11+
HIGH 7.5
CVE-2022-3488EPSS 19%
Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can c…
Bind
No fix yet
HIGH 7.5
CVE-2022-3094EPSS 13%
Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack …
Bind
9.16.37 / 9.18.11+
HIGH 8.2
CVE-2022-2881
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
Bind
9.18.7 / 9.19.5+
HIGH 7.5
CVE-2022-2906
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attac…
Bind
9.18.7 / 9.19.5+
HIGH 7.5
CVE-2022-1183EPSS 6%
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those t…
Bind
after 9.18.2
HIGH 7.5
CVE-2022-0635
Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate …
Bind
Mitigation only
HIGH 7.5
CVE-2022-0667
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
Bind
No fix yet
HIGH 7.5
CVE-2018-5742
While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat ver…
Bind
after 9.9.4-72
HIGH 7.5
CVE-2019-6475
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zone is similar to a zone of ty…
Bind
after 9.15.4
HIGH 7.5
CVE-2019-6476
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than …
Bind
after 9.15.4
MEDIUM 6.5
CVE-2019-6472
A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.…
Kea
after 1.5.0
MEDIUM 6.5
CVE-2019-6474
A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are reje…
Kea
after 1.5.0
HIGH 7.5
CVE-2019-6469
An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failure when processing a response …
Bind
Mitigation only
HIGH 7.5
CVE-2019-6467EPSS 5%
A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespace used by nxdomain-redirect i…
Bind
after 9.13.7