Junglewise Threat Intelligence

CVE-2026-3592: ISC BIND resource exhaustion in DNS resolver

CVE-2026-3592 · Severity: medium · CVSS 5.3 · Published 2026-05-20

Technologies: Isc BIND 9. Vendors: Isc.

Executive brief

BIND, a widely used system for translating website names into IP addresses, is vulnerable to a resource exhaustion attack. An attacker can create a malicious DNS zone that, when queried by a BIND resolver, causes the system to consume excessive processing power or memory. This can lead to significant performance degradation or a denial of service for users relying on that DNS server.

Technical details

BIND 9 resolvers are susceptible to a Denial of Service (DoS) vulnerability classified as Early Amplification (CWE-408). The vulnerability is triggered when a resolver attempts to process queries for a specially crafted malicious DNS zone. This results in disproportionate resource consumption (CPU or memory) relative to the query size. The attack can be launched remotely over the network without authentication. ISC has released patches in versions 9.18.49, 9.20.23, and 9.21.22 to address this issue.

Affected products

  • ISC BIND 9 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, 9.20.9-S1 through 9.20.22-S1

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: patched
  • 2026-05-20: advisory

References

Related threats