<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:47:13 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-81736</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-81736</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:25: bind, Alpaquita:stream: bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:25: bind, Alpaquita:stream: bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-81736</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1192 — De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1192</link>
      <description>certfr-2026-avi-1192</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1192</guid>
    </item>
    <item>
      <title>EUVD-2026-371426</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-371426</link>
      <description>EUVD-2026-371426</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-371426</guid>
    </item>
    <item>
      <title>fkie_cve-2026-81736</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-81736</link>
      <description>&lt;p&gt;If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-81736</guid>
    </item>
    <item>
      <title>GHSA-hjmx-qf9h-v7mw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hjmx-qf9h-v7mw</link>
      <description>&lt;p&gt;If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hjmx-qf9h-v7mw</guid>
    </item>
    <item>
      <title>OESA-2026-4191 — bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: bind&lt;/p&gt;
&lt;p&gt;Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-80274)&lt;/p&gt;
&lt;p&gt;A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-81563)&lt;/p&gt;
&lt;p&gt;If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: bind&lt;/p&gt;
&lt;p&gt;Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-80274)&lt;/p&gt;
&lt;p&gt;A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.(CVE-2026-81563)&lt;/p&gt;
&lt;p&gt;If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response.
This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4191</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11916-1 — bind-9.20.29-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11916-1</link>
      <description>&lt;p&gt;bind-9.20.29-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind-9.20.29-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11916-1</guid>
    </item>
    <item>
      <title>RHSA-2026:68279 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:68279</link>
      <description>&lt;p&gt;bind: BIND: Unauthorized zone content updates via unauthenticated IXFR deltas bind9: bind: BIND 9: Denial of Service via crafted DNSSEC responses bind: BIND: Denial of Service via malformed DNS64 responses bind9: bind: BIND 9: Denial of Service via 16-bit length truncation in DNS negative cache handling bind: BIND: Denial of Service via invalid DNSSEC records bind9: bind: BIND 9: DNS wildcard record existence can be masked by an attacker via inapplicable NSEC records bind: BIND 9: Denial of Service via crafted query responses bind: BIND: Denial of Service via TKEY query with specific configuration bind9: bind: BIND 9: DNSSEC bypass via NSEC3 insecure-referral proof bind: BIND: Remote Denial of Service via crafted DNS-over-HTTPS request bind: BIND: DNS cache poisoning via malformed zone insertion bind: BIND: Denial of Service via crafted DNSSEC reply bind: BIND resolver: Denial of Service due to resource exhaustion in SVCB/HTTPS AliasMode processing bind: BIND 9: Remote Denial of Service via cached SVCB/HTTPS AliasMode records&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind: BIND: Unauthorized zone content updates via unauthenticated IXFR deltas bind9: bind: BIND 9: Denial of Service via crafted DNSSEC responses bind: BIND: Denial of Service via malformed DNS64 responses bind9: bind: BIND 9: Denial of Service via 16-bit length truncation in DNS negative cache handling bind: BIND: Denial of Service via invalid DNSSEC records bind9: bind: BIND 9: DNS wildcard record existence can be masked by an attacker via inapplicable NSEC records bind: BIND 9: Denial of Service via crafted query responses bind: BIND: Denial of Service via TKEY query with specific configuration bind9: bind: BIND 9: DNSSEC bypass via NSEC3 insecure-referral proof bind: BIND: Remote Denial of Service via crafted DNS-over-HTTPS request bind: BIND: DNS cache poisoning via malformed zone insertion bind: BIND: Denial of Service via crafted DNSSEC reply bind: BIND resolver: Denial of Service due to resource exhaustion in SVCB/HTTPS AliasMode processing bind: BIND 9: Remote Denial of Service via cached SVCB/HTTPS AliasMode records&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:68279</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-81736</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-81736</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:Pro:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp and 2 more&lt;/p&gt;
&lt;p&gt;If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:Pro:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp and 2 more&lt;/p&gt;
&lt;p&gt;If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-81736</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3420 — Internet Systems Consortium BIND: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3420</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3420</guid>
    </item>
  </channel>
</rss>
