Use-after-free in ISC BIND - CVE-2026-3593
Published: May 22, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to use-after-free in the DNS-over-HTTPS implementation when processing crafted HTTP/2 traffic sent to a DNS-over-HTTPS endpoint. A remote attacker can send crafted HTTP/2 traffic to disclose sensitive information and cause a denial of service.
Both authoritative servers and resolvers are affected.