CVE Tools

Bind 9

83 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Bind 9, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Bind 9 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Bind 9 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-012
2025-020
2025-030
2025-040
2025-051
2025-060
2025-072
2025-080
2025-090
2025-103
2025-110
2025-120
2026-011
2026-020
2026-034
2026-040
2026-056
2026-060
2026-079
2026-080
2026-0914

Severity

How the 83 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High5769%
  • Medium2530%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting Bind 9.

  1. CVE-2026-77119NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets5.9
  2. CVE-2026-75029Message parser retains every identical singleton RDATA, enabling wire-to-work amplification5.3
  3. CVE-2026-19668Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching5.3
  4. CVE-2026-19033Unauthenticated IXFR deltas are applied to the live zone before TSIG verification6.5
  5. CVE-2026-80274Validating resolver can abort while caching a mismatched NOQNAME proof7.5
  6. CVE-2026-76163named aborts on a TKEY query when the user configuration has no global options statement7.5
  7. CVE-2026-19666Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path7.5
  8. CVE-2026-81563SVCB AliasMode additional-data error leaks qpcache references7.5
  9. CVE-2026-78301Out-of-zone database nodes can become authoritative zone cuts5.8
  10. CVE-2026-77692Unauthenticated remote crash of named via a single DoH SIG(0) request7.5
  11. CVE-2026-19941checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof5.9
  12. CVE-2026-19662qpcache NOQNAME proof use-after-free crashes recursive resolver5.9
  13. CVE-2026-19667Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`7.5
  14. CVE-2026-81736Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees7.5
  15. CVE-2026-13321DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field8.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store