Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1519

33
FAUCET Score

CVE-2026-1519 is a high-severity vulnerability affecting multiple versions of BIND 9 resolvers performing DNSSEC validation. A maliciously crafted DNS zone can cause the resolver to consume excessive CPU resources, potentially leading to a denial of service. Rated 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), this vulnerability can be exploited remotely with low attack complexity, requiring no privileges or user interaction, and primarily impacts availability. While there is no known active exploitation, public exploit code is currently unavailable, and it is not listed on the KEV catalog. Community discussion indicates awareness, with media coverage from sources like Ubuntu Security and seclists.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.11.0, <= 9.16.50CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
>= 9.18.0, < 9.18.47CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
>= 9.20.0, < 9.20.21CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
>= 9.21.0, < 9.21.20CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.54%
Probability of exploitation in next 30 days
EPSS Percentile
72.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0155 is in the 54th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

alistgopatch availablevia llm_extracted
Fixed in: 9.20.20
View patch
ansiblepatch availablevia llm_extracted
View patch
freshrsspatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: cbl2 bind 9.16.50-3 on CBL Mariner 2.0Fixed in: 9.16.50-4
microsoftpatch availablevia msrc
Product: 21082-17084Fixed in: 9.20.21-1
microsoftpatch availablevia msrc
Product: azl3 bind 9.20.18-1 on Azure Linux 3.0Fixed in: 9.20.21-1
microsoftpatch availablevia msrc
Product: 21081-17086Fixed in: 9.16.50-4
ubuntupatch availablevia ubuntu_usn
Product: bind9 (questing)Fixed in: 1:9.20.11-1ubuntu2.2
ubuntupatch availablevia ubuntu_usn
Product: bind9 (noble)Fixed in: 1:9.18.39-0ubuntu0.24.04.3
ubuntupatch availablevia ubuntu_usn
Product: bind9 (jammy)Fixed in: 1:9.18.39-0ubuntu0.22.04.3

Vendor Advisories (5)

ubuntuUSN-8124-1

Bind vulnerabilities

Mar 25, 2026
ansiblellm-ansible-8fddcd9f01b420b5

USN-8124-1: Bind vulnerabilities

Mar 25, 2026
freshrssllm-freshrss-1559427523e24bf6

USN-8124-1: Bind vulnerabilities

Mar 25, 2026
microsoft2026-Mar/CVE-2026-1519Important

Excessive NSEC3 iterations cause high CPU load during insecure delegation validation

Mar 10, 2026
alistgollm-alistgo-ad0b45537e40b0eb

Excessive NSEC3 iterations cause high CPU load during insecure delegation validation

References

access.redhat.com / errata/RHSA-2026:11371
access.redhat.com / errata/RHSA-2026:11372
access.redhat.com / errata/RHSA-2026:15890
access.redhat.com / errata/RHSA-2026:16060
access.redhat.com / errata/RHSA-2026:16064
access.redhat.com / errata/RHSA-2026:24500
access.redhat.com / errata/RHSA-2026:24851
access.redhat.com / errata/RHSA-2026:24934
access.redhat.com / errata/RHSA-2026:25083
access.redhat.com / errata/RHSA-2026:25171
access.redhat.com / errata/RHSA-2026:25214
access.redhat.com / errata/RHSA-2026:29110
access.redhat.com / errata/RHSA-2026:29863
access.redhat.com / errata/RHSA-2026:34048
access.redhat.com / errata/RHSA-2026:36610
access.redhat.com / errata/RHSA-2026:40021
access.redhat.com / errata/RHSA-2026:6935
access.redhat.com / errata/RHSA-2026:7915
access.redhat.com / errata/RHSA-2026:8075
access.redhat.com / errata/RHSA-2026:8155
access.redhat.com / errata/RHSA-2026:8312
access.redhat.com / errata/RHSA-2026:8352
access.redhat.com / security/cve/CVE-2026-1519
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-1519.json
lists.debian.org / debian-lts-announce/2026/04/msg00008.html
Issue TrackingThird Party Advisory
downloads.isc.org / isc/bind9/9.18.47
Patch
downloads.isc.org / isc/bind9/9.20.21
Patch
downloads.isc.org / isc/bind9/9.21.20
Patch
kb.isc.org / docs/cve-2026-1519
Vendor Advisory