CVE-2026-3591 is a use-after-return vulnerability in the BIND 9 `named` server, affecting versions 9.20.0-9.20.20, 9.21.0-9.21.19, and 9.20.9-S1-9.20.20-S1. An unauthenticated attacker can exploit this by sending a specially-crafted DNS request signed with SIG(0), causing an Access Control List (ACL) to improperly match an IP address. Rated Medium severity (CVSS 5.4), this could lead to unauthorized access if the server utilizes a default-allow ACL. Currently, there is no evidence of active exploitation, no public exploit code available, and community discussion remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.20.0, < 9.20.21CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.21.0, < 9.21.20CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Bind vulnerabilities
Mar 25, 2026USN-8124-1: Bind vulnerabilities
Mar 25, 2026USN-8124-1: Bind vulnerabilities
Mar 25, 2026A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
Mar 10, 2026A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass