Junglewise Threat Intelligence

CVE-2026-11331: ISC BIND 9 RPZ policy bypass and denial of service

CVE-2026-11331 · Severity: high · CVSS 7.5 · Published 2026-07-22

Technologies: Isc BIND 9. Vendors: Isc.

Executive brief

A vulnerability has been identified in BIND 9, a widely used system for translating human-readable domain names into IP addresses. An attacker can send specially crafted network requests that bypass security filtering rules (Response Policy Zones) or cause the DNS service to crash. This could allow users to access restricted websites or result in a service outage for the organization.

Technical details

A vulnerability exists in BIND 9's Response Policy Zone (RPZ) processing when handling wildcard CNAME policies. By crafting query names long enough to trigger a NAMETOOLONG error condition, an attacker can cause the resolver to fail to apply the intended RPZ rule or trigger an unexpected process exit. The issue stems from improper filtering of special elements (CWE-790) during the error handling phase of RPZ lookups. This is exploitable remotely via network queries without authentication. Patches are available in BIND versions 9.20.26, 9.21.24, and 9.20.26-S1.

Affected products

  • ISC BIND 9 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.24-S1

Timeline

  • 2026-07-15: other: Early Notification
  • 2026-07-22: disclosed: Public disclosure
  • 2026-07-22: patched: Patched versions released

References

Related threats