CVE-2026-1519 is a high-severity vulnerability affecting multiple versions of BIND 9 resolvers performing DNSSEC validation. A maliciously crafted DNS zone can cause the resolver to consume excessive CPU resources, potentially leading to a denial of service. Rated 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), this vulnerability can be exploited remotely with low attack complexity, requiring no privileges or user interaction, and primarily impacts availability. While there is no known active exploitation, public exploit code is currently unavailable, and it is not listed on the KEV catalog. Community discussion indicates awareness, with media coverage from sources like Ubuntu Security and seclists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.11.0, <= 9.16.50CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.18.0, < 9.18.47CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.20.0, < 9.20.21CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.21.0, < 9.21.20CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Bind vulnerabilities
Mar 25, 2026USN-8124-1: Bind vulnerabilities
Mar 25, 2026USN-8124-1: Bind vulnerabilities
Mar 25, 2026Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
Mar 10, 2026Excessive NSEC3 iterations cause high CPU load during insecure delegation validation