Junglewise Threat Intelligence

CVE-2026-3593: ISC BIND 9 use-after-free in DNS-over-HTTPS implementation

CVE-2026-3593 · Severity: high · CVSS 7.4 · Published 2026-05-20

Technologies: Isc BIND 9. Vendors: Isc.

Executive brief

A vulnerability has been identified in BIND 9, the most widely used Domain Name System (DNS) software on the internet. This flaw affects the DNS-over-HTTPS (DoH) feature, which is used to encrypt web-based DNS queries. An attacker could exploit this to cause memory corruption, potentially leading to service crashes or unauthorized access to sensitive information, impacting both authoritative and resolver servers.

Technical details

A heap use-after-free vulnerability (CWE-416) exists within the DNS-over-HTTPS implementation of BIND 9. The flaw is triggered when a remote attacker sends specially crafted HTTP/2 traffic to a DNS-over-HTTPS endpoint. This can lead to memory corruption, affecting both authoritative servers and resolvers. While the attack is network-reachable and requires no authentication, it has a high attack complexity. Users are advised to upgrade to BIND versions 9.20.23, 9.21.22, or 9.20.23-S1. As a workaround, disabling DNS-over-HTTPS will mitigate the risk.

Affected products

  • ISC BIND 9 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.20.9-S1 through 9.20.22-S1

Timeline

  • 2026-05-13: other: Early notification provided
  • 2026-05-20: disclosed: Public disclosure of the vulnerability
  • 2026-05-20: patched: Patched versions 9.20.23 and 9.21.22 released

References

Related threats