CVE-2026-80274
Validating resolver can abort while caching a mismatched NOQNAME proof
Description
If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
In plain language
AI Act nowBIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1 can be crashed remotely, so small businesses running their own DNS resolver should act now.
Unauthenticated network denial of service in BIND 9 validating resolvers: a crafted DNSSEC response with mismatched NOQNAME proof data can trigger an unexpected process exit.
What to do now
- Check the installed BIND 9 version with
named -vand compare it with the affected versions in the advisory. - Upgrade a standard 9.20 installation to 9.20.29, a 9.21 installation to 9.21.26, or an S1 installation to 9.20.29-S1.
- Restart BIND 9 after the upgrade and confirm DNS lookups work from both internal systems and the internet-facing services that rely on it.
- If you run an older 9.11 through 9.18 release, arrange a supported-version upgrade with your DNS provider or administrator because no temporary workaround is known.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacksen·The Hacker News· Exploited Cisco Identity Services Engine zero-day
- ISC Patches 14 Vulnerabilities in BIND 9 Security Updateen-us·SecurityWeek· Patch BIND 9 ddos-botnet
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPSen·The Hacker News· Patch BIND 9 network-edge
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-80274 and every CVE in our database. Create a free account — no credit card required.
Create Free Account