← Vulnerability feed

Vulnerability record · CVE-2026-1519 · published 25 March 2026

CVE-2026-1519: Isc bind allocation without limits vulnerability

Isc · Bind

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

7.5 CVSS 3.1 High EPSS 1.6% · top 25.2% CWE-606 · CWE-606CWE-770 · Allocation without limits
7.5CVSS 3.1 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
17 Sep 2026Last modified by NVD

Description

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://downloads.isc.org/isc/bind9/9.18.47 Patch
https://downloads.isc.org/isc/bind9/9.20.21 Patch
https://downloads.isc.org/isc/bind9/9.21.20 Patch
https://kb.isc.org/docs/cve-2026-1519 Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/04/msg00008.html Issue TrackingThird Party Advisory
https://access.redhat.com/errata/RHSA-2026:11371
https://access.redhat.com/errata/RHSA-2026:11372
https://access.redhat.com/errata/RHSA-2026:15890
https://access.redhat.com/errata/RHSA-2026:16060
https://access.redhat.com/errata/RHSA-2026:16064
https://access.redhat.com/errata/RHSA-2026:24500
https://access.redhat.com/errata/RHSA-2026:24851
https://access.redhat.com/errata/RHSA-2026:24934
https://access.redhat.com/errata/RHSA-2026:25083
https://access.redhat.com/errata/RHSA-2026:25171
https://access.redhat.com/errata/RHSA-2026:25214
https://access.redhat.com/errata/RHSA-2026:29110
https://access.redhat.com/errata/RHSA-2026:29863
https://access.redhat.com/errata/RHSA-2026:34048
https://access.redhat.com/errata/RHSA-2026:36610
https://access.redhat.com/errata/RHSA-2026:40021
https://access.redhat.com/errata/RHSA-2026:43226
https://access.redhat.com/errata/RHSA-2026:60019
https://access.redhat.com/errata/RHSA-2026:62549
https://access.redhat.com/errata/RHSA-2026:65851
https://access.redhat.com/errata/RHSA-2026:6935
https://access.redhat.com/errata/RHSA-2026:7915
https://access.redhat.com/errata/RHSA-2026:8075
https://access.redhat.com/errata/RHSA-2026:8155
https://access.redhat.com/errata/RHSA-2026:8312
https://access.redhat.com/errata/RHSA-2026:8352
https://access.redhat.com/security/cve/CVE-2026-1519
https://bugzilla.redhat.com/show_bug.cgi?id=2451305
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1519.json

Track CVE-2026-1519 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2026-1519), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.