Input validation error in ISC BIND - CVE-2026-13321
Published: July 23, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to poison the DNS cache and cause authenticated denial-of-service responses.
The vulnerability exists due to improper input validation in DNSSEC NSEC record validation when processing validly signed NSEC records whose next domain name points outside the signer's zone. A remote attacker can craft malicious NSEC records to poison the DNS cache and cause authenticated denial-of-service responses.
Exploitation requires control of any DNSSEC-signed zone.