Junglewise Threat Intelligence

CVE-2026-13204: ISC BIND 9 denial of service via NSEC and NSEC3 assertion failure

CVE-2026-13204 · Severity: high · CVSS 7.5 · Published 2026-07-22

Technologies: Isc BIND 9 Supported Preview Edition, Isc BIND 9. Vendors: Isc.

Executive brief

ISC BIND 9 is a widely used software suite for managing Domain Name System (DNS) services, which translate human-readable domain names into IP addresses. A vulnerability has been identified where processing specific DNS security records can cause the server to crash unexpectedly. This results in a denial-of-service, preventing users from accessing websites or services that rely on the affected DNS server.

Technical details

A reachable assertion vulnerability (CWE-617) exists in BIND 9 during DNSSEC validation. The issue occurs when a provably insecure domain is covered by both NSEC and NSEC3 records at the parent zone, but an RRSIG exists for only one of these types. When BIND attempts to validate this proof, it may encounter an unexpected state and exit with an assertion failure. This is a remote, unauthenticated attack vector that leads to a complete loss of availability (DoS). The vulnerability is fixed in BIND versions 9.20.26, 9.21.24, and 9.20.26-S1.

Affected products

  • ISC BIND 9 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23
  • ISC BIND 9 Supported Preview Edition 9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.24-S1

Timeline

  • 2026-07-15: other: Early Notification
  • 2026-07-22: advisory: Public disclosure
  • 2026-07-22: patched: Fixed versions released

References

Related threats