CVE-2025-8677 is a high-severity vulnerability affecting BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, and 9.21.0 through 9.21.12, including their S1 variants. This flaw allows an unauthenticated attacker to cause CPU exhaustion by querying a specially crafted zone containing malformed DNSKEY records. With a CVSS score of 7.5, the vulnerability has a high impact on availability due to the potential for denial of service. Currently, there is no known active exploitation, public exploit code, or significant community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ISC | BIND 9 | >= 9.18.0, <= 9.18.39, >= 9.18.11-S1, <= 9.18.39-S1, >= 9.20.0, <= 9.20.13, >= 9.20.9-S1, <= 9.20.13-S1, >= 9.21.0, <= 9.21.12CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026bind: Resource exhaustion via malformed DNSKEY handling
Oct 22, 2025Resource exhaustion via malformed DNSKEY handling
Oct 14, 2025Resource exhaustion via malformed DNSKEY handling