Input validation error in ISC BIND - CVE-2026-10723
Published: July 23, 2026
ISC BIND
Detailed vulnerability description
The vulnerability allows a remote attacker to forge authenticated NXDOMAIN responses.
The vulnerability exists due to improper validation of child-zone NSEC3 records in BIND 9 when processing DNSSEC records. A remote attacker can provide incorrect child-zone NSEC3 records to forge authenticated NXDOMAIN responses.
The issue can affect sibling zones.