Reachable assertion in ISC BIND - CVE-2026-13204
Published: July 23, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an assertion failure in the DNSSEC validation logic when validating a provably insecure domain covered by both an NSEC and NSEC3 record at the parent with an RRSIG for only one of these types. A remote attacker can provide crafted DNS data to cause a denial of service.