CVE Tools

BIND9

25 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for BIND9, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

BIND9 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
BIND9 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High1768%
  • Medium832%

Latest CVEs

The 15 most recently published vulnerabilities affecting BIND9.

  1. CVE-2022-38178Memory leaks in EdDSA DNSSEC verification code7.5
  2. CVE-2022-3080BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly7.5
  3. CVE-2022-38177Memory leak in ECDSA DNSSEC verification code7.5
  4. CVE-2022-2906Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only)7.5
  5. CVE-2022-2881Buffer overread in statistics channel code5.5
  6. CVE-2022-2795Processing large delegations may severely degrade resolver performance5.3
  7. CVE-2022-1183Destroying a TLS session early causes assertion failure7.5
  8. CVE-2021-25219Lame cache can be abused to severely degrade resolver performance5.3
  9. CVE-2021-25218A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use7.5
  10. CVE-2021-25216A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack8.1
  11. CVE-2021-25214A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly6.5
  12. CVE-2021-25215An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself7.5
  13. CVE-2020-8625A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack8.1
  14. CVE-2020-8624update-policy rules of type "subdomain" are enforced incorrectly4.3
  15. CVE-2020-8622A truncated TSIG response can lead to an assertion failure6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store