CVE-2026-1519

Source
https://cve.org/CVERecord?id=CVE-2026-1519
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1519.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-1519
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLSA (5)
DEBIAN (1)
MGASA (1)
MINI (1)
OESA (5)
openSUSE (2)
RHSA (18)
RLSA (5)
SUSE (8)
UBUNTU (1)
Related
Published
2026-03-25T14:16:33Z
Modified
2026-09-19T08:14:23Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

References

Affected packages

Git / github.com/isc-projects/bind9

Affected ranges

Type
GIT
Repo
https://github.com/isc-projects/bind9
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "9.11.0"
        },
        {
            "last_affected":  "9.16.50"
        },
        {
            "introduced":  "9.18.0"
        },
        {
            "fixed":  "9.18.47"
        },
        {
            "introduced":  "9.20.0"
        },
        {
            "fixed":  "9.20.21"
        },
        {
            "introduced":  "9.21.0"
        },
        {
            "fixed":  "9.21.20"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v9.*
v9.18.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1519.json"

Git / gitlab.isc.org/isc-projects/bind9

Affected ranges

Type
GIT
Repo
https://gitlab.isc.org/isc-projects/bind9
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "9.11.0"
        },
        {
            "last_affected":  "9.16.50"
        },
        {
            "introduced":  "9.18.0"
        },
        {
            "fixed":  "9.18.47"
        },
        {
            "introduced":  "9.20.0"
        },
        {
            "fixed":  "9.20.21"
        },
        {
            "introduced":  "9.21.0"
        },
        {
            "fixed":  "9.21.20"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v9.*
v9.18.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-1519.json"