Junglewise Threat Intelligence

CVE-2026-19941: ISC BIND named NSEC wildcard masking vulnerability

CVE-2026-19941 · Severity: medium · CVSS 5.9 · Published 2026-09-16

Executive brief

BIND is widely used DNS resolver software that handles domain name lookups for millions of network requests daily. This vulnerability allows an attacker to forge DNS proof records to hide legitimate wildcard domain entries, potentially redirecting traffic or causing service failures for affected domains. Organizations running vulnerable BIND versions should update immediately to restore DNS security.

Technical details

This is a DNSSEC validation flaw in BIND's named resolver where an inapplicable NSEC (Next Secure) record can be incorrectly accepted as cryptographic proof that a wildcard record does not exist at a given zone level. The vulnerability affects BIND's NSEC record validation logic when processing responses from authoritative nameservers. An attacker positioned at the same or upstream level of the zone hierarchy can exploit this to mask the existence of a legitimate wildcard record, leading to DNS spoofing or denial of service. Patches are available in versions 9.18.51+, 9.20.28+, 9.21.26+, and corresponding -S1 stable releases.

Affected products

  • ISC BIND 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.27-S1

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: BIND 9.20.29 and 9.21.26 released with fixes

References

Related threats