Resource exhaustion in ISC BIND - CVE-2026-5950
Published: May 22, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper control of resource consumption in the resolver state machine bad-server handling in BIND 9 when processing queries that trigger specific retry conditions. A remote attacker can send specially crafted queries to cause a denial of service.
Resolvers are affected, while authoritative services are believed to be unaffected.