CVE-2026-13204

HIGH

Unexpected exit in certain situations with NSEC and NSEC3 both present

Title source: cna
STIX 2.1

Description

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
CVE-2026-13204
https://kb.isc.org/docs/cve-2026-13204

Scores

CVSS v3 7.5
EPSS 0.0051
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (5)
ISC/BIND 9 9.11.0 - 9.18.50
ISC/BIND 9 9.11.3-S1 - 9.18.50-S1
ISC/BIND 9 9.20.0 - 9.20.24
ISC/BIND 9 9.20.9-S1 - 9.20.24-S1
ISC/BIND 9 9.21.0 - 9.21.23
Published Jul 22, 2026
Tracked Since Jul 22, 2026