Insufficient verification of data authenticity in ISC BIND - CVE-2026-19941
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to poison the DNS cache.
The vulnerability exists due to insufficient verification of data authenticity in the checkwildcard() function of the named resolver when validating wildcard-nonexistence proofs. A remote attacker can provide an out-of-zone NSEC record as proof that a wildcard does not exist to poison the DNS cache.
Exploitation requires control at the same or an upstream level of the zone name.