CVE-2026-11605
Received Received - Intake

Resource Exhaustion in BIND Due to Unnecessary DNSSEC Validation

Vulnerability report for CVE-2026-11605, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Internet Systems Consortium (ISC)

Description

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
isc bind From 9.20.0 (inc) to 9.20.24 (inc)
isc bind From 9.21.0 (inc) to 9.21.23 (inc)
isc bind From 9.20.9-S1 (inc) to 9.20.24-S1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-408 The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-11605 is a resource exhaustion vulnerability in BIND 9 related to DNSSEC validation. BIND unnecessarily validates all RRSIG records in DNS responses, even when they are not required. This causes excessive CPU usage, potentially leading to a denial-of-service condition.

Detection Guidance

Monitor CPU usage spikes during DNS queries, especially when validating DNSSEC-signed responses. Check BIND version with 'named -v' to confirm if affected versions (9.20.0-9.20.24, 9.21.0-9.21.23, or 9.20.9-S1-9.20.24-S1) are running.

Impact Analysis

This vulnerability can cause high CPU usage on systems running vulnerable BIND versions, leading to degraded performance or service outages. Attackers could exploit it to disrupt DNS services by sending crafted responses with many unnecessary RRSIG records.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by causing service disruptions due to CPU exhaustion, potentially leading to downtime or degraded performance of DNS services. GDPR requires maintaining system availability, while HIPAA mandates reliable access to critical systems. Exploitation could disrupt these requirements.

Mitigation Strategies

Upgrade BIND to patched versions: 9.20.26, 9.21.24, or 9.20.26-S1 immediately. Disable unnecessary DNSSEC validation if possible until upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11605. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart