CVE-2026-11331
Received Received - Intake

RPZ Wildcard CNAME Policy Handling Flaw in BIND 9

Vulnerability report for CVE-2026-11331, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Internet Systems Consortium (ISC)

Description

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
isc bind From 9.16.0 (inc) to 9.18.50 (inc)
isc bind From 9.20.0 (inc) to 9.20.24 (inc)
isc bind From 9.21.0 (inc) to 9.21.23 (inc)
isc bind From 9.16.8-S1 (inc) to 9.18.50-S1 (inc)
isc bind From 9.20.9-S1 (inc) to 9.20.24-S1 (inc)
isc bind 9.20.26
isc bind 9.21.24

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-790 The product receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-11331 is a high-severity flaw in BIND 9 DNS software. It allows an attacker to bypass RPZ wildcard CNAME policies by crafting overly long query names that trigger a NAMETOOLONG error during RPZ processing. This improper handling may let the attacker evade RPZ rules or cause BIND 9 to crash unexpectedly.

Detection Guidance

Detecting this vulnerability requires checking the BIND 9 version in use. Run 'named -v' or check package versions with 'rpm -qa | grep bind' or 'dpkg -l | grep bind'. If your version falls within 9.16.0-9.18.50, 9.20.0-9.20.24, or 9.21.0-9.21.23, the system is vulnerable.

Impact Analysis

This vulnerability could let attackers bypass DNS-based security policies, potentially allowing malicious domains to resolve. It may also cause BIND 9 to crash, disrupting DNS services. Systems using vulnerable BIND 9 versions are at risk of unauthorized access or service outages.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR or HIPAA by potentially allowing unauthorized access to DNS resolution data if RPZ policies are bypassed. Unauthorized DNS queries might expose sensitive information or enable data exfiltration, violating confidentiality requirements in these regulations.

Mitigation Strategies

Upgrade BIND 9 to a patched version: 9.20.26, 9.21.24, or their Supported Preview Edition equivalents. Download from https://downloads.isc.org/isc/bind9/9.20.26 or https://downloads.isc.org/isc/bind9/9.21.24. No workarounds are available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11331. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart