<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:08:49.112698+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-80274</id>
    <title>BELL-CVE-2026-80274</title>
    <updated>2026-10-02T22:08:49.231707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: bind, Alpaquita:25: bind, Alpaquita:stream: bind</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-80274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1192</id>
    <title>certfr-2026-avi-1192 — De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de…</title>
    <updated>2026-10-02T22:08:49.231756+00:00</updated>
    <content>certfr-2026-avi-1192</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1192"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-371307</id>
    <title>EUVD-2026-371307</title>
    <updated>2026-10-02T22:08:49.231776+00:00</updated>
    <content>EUVD-2026-371307</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-371307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-80274</id>
    <title>fkie_cve-2026-80274</title>
    <updated>2026-10-02T22:08:49.231788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-80274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m66j-g9q7-jxjg</id>
    <title>GHSA-m66j-g9q7-jxjg</title>
    <updated>2026-10-02T22:08:49.231812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m66j-g9q7-jxjg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-80274</id>
    <title>msrc_CVE-2026-80274 — Validating resolver can abort while caching a mismatched NOQNAME proof</title>
    <updated>2026-10-02T22:08:49.231828+00:00</updated>
    <content>msrc_CVE-2026-80274</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-80274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4190</id>
    <title>OESA-2026-4190 — bind security update</title>
    <updated>2026-10-02T22:08:49.231843+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: bind</p>
<p>Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.

Security Fix(es):</p>
<p>If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-80274)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4190"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11916-1</id>
    <title>openSUSE-SU-2026:11916-1 — bind-9.20.29-1.1 on GA media</title>
    <updated>2026-10-02T22:08:49.231867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind-9.20.29-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11916-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:68279</id>
    <title>RHSA-2026:68279 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T22:08:49.231886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind: BIND: Unauthorized zone content updates via unauthenticated IXFR deltas bind9: bind: BIND 9: Denial of Service via crafted DNSSEC responses bind: BIND: Denial of Service via malformed DNS64 responses bind9: bind: BIND 9: Denial of Service via 16-bit length truncation in DNS negative cache handling bind: BIND: Denial of Service via invalid DNSSEC records bind9: bind: BIND 9: DNS wildcard record existence can be masked by an attacker via inapplicable NSEC records bind: BIND 9: Denial of Service via crafted query responses bind: BIND: Denial of Service via TKEY query with specific configuration bind9: bind: BIND 9: DNSSEC bypass via NSEC3 insecure-referral proof bind: BIND: Remote Denial of Service via crafted DNS-over-HTTPS request bind: BIND: DNS cache poisoning via malformed zone insertion bind: BIND: Denial of Service via crafted DNSSEC reply bind: BIND resolver: Denial of Service due to resource exhaustion in SVCB/HTTPS AliasMode processing bind: BIND 9: Remote Denial of Service via cached SVCB/HTTPS AliasMode records</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:68279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80274</id>
    <title>UBUNTU-CVE-2026-80274</title>
    <updated>2026-10-02T22:08:49.231918+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:Pro:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp and 2 more</p>
<p>If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-80274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3420</id>
    <title>WID-SEC-W-2026-3420 — Internet Systems Consortium BIND: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:08:49.231952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder Denial-of-Service-Zustände herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3420"/>
  </entry>
</feed>
