Improper Check or Handling of Exceptional Conditions in ISC BIND - CVE-2026-11331
Published: July 23, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass RPZ rules.
The vulnerability exists due to improper error handling in RPZ processing when processing sufficiently long query names that trigger a NAMETOOLONG condition with wildcard CNAME policies. A remote attacker can send a crafted query name to bypass RPZ rules.
The issue only affects resolvers that use RPZ with wildcard CNAME policies.