Junglewise Threat Intelligence

CVE-2026-13321: ISC BIND DNSSEC validation bypass in NSEC records

CVE-2026-13321 · Severity: high · CVSS 8.6 · Published 2026-07-22

Technologies: Isc BIND 9. Vendors: Isc.

Executive brief

BIND 9, a widely used system for translating human-readable domain names into IP addresses, contains a vulnerability in how it validates security records. An attacker can exploit this to trick the system into believing certain websites or services do not exist, even when they are legitimate. This can lead to a denial of service for specific web resources or redirected traffic, potentially disrupting business operations and user access to services.

Technical details

A vulnerability exists in the BIND 9 resolver's DNSSEC validation logic (CWE-346). The resolver accepts validly-signed NSEC records where the 'Next Domain Name' field points to a location outside the signer's authoritative zone. A remote, unauthenticated attacker controlling a DNSSEC-signed zone can craft malicious NSEC records that span into victim zones. This allows the attacker to perform cross-zone cache poisoning, providing authenticated denial-of-service responses (with the AD bit set) for records they do not own. The issue is resolved in BIND versions 9.20.26, 9.21.24, and 9.20.26-S1.

Affected products

  • ISC BIND 9 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.24-S1

Timeline

  • 2026-07-15: other: Early Notification
  • 2026-07-22: disclosed: Public disclosure
  • 2026-07-22: patched: Patched versions 9.20.26 and 9.21.24 released

References

Related threats