CVE-2026-13321
Received Received - Intake

Out-of-Zone NSEC Record Handling in BIND Resolver

Vulnerability report for CVE-2026-13321, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Internet Systems Consortium (ISC)

Description

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
isc bind From 9.11.0 (inc) to 9.18.50 (inc)
isc bind From 9.20.0 (inc) to 9.20.24 (inc)
isc bind From 9.21.0 (inc) to 9.21.23 (inc)
isc bind From 9.11.3-S1 (inc) to 9.18.50-S1 (inc)
isc bind From 9.20.9-S1 (inc) to 9.20.24-S1 (inc)
isc bind 9.20.26
isc bind 9.21.24
isc bind 9.20.26-s1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-13321 is a DNSSEC validation bypass in BIND 9 where the resolver accepts validly-signed NSEC records with a 'Next Domain Name' field pointing outside the signer's zone. This allows attackers to craft NSEC records spanning into victim zones, enabling cross-zone cache poisoning with authenticated denial-of-service responses.

Detection Guidance

To detect this vulnerability, check your BIND version against affected releases (9.11.0-9.18.50, 9.20.0-9.20.24, 9.21.0-9.21.23, and their S1 variants). Use the command 'named -v' to display the installed version. Monitor DNSSEC validation logs for unexpected NSEC record handling or cache poisoning attempts.

Impact Analysis

This vulnerability can be exploited remotely without authentication to poison DNS caches, redirecting users to malicious sites or disrupting services. It affects DNS resolution for domains using vulnerable BIND versions, potentially leading to data interception or service outages.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling DNS cache poisoning attacks that manipulate DNS responses. Such attacks might lead to unauthorized data exposure or service disruption, which are critical concerns under these regulations. The ability to craft authenticated denial-of-service responses could also interfere with logging and monitoring requirements.

Mitigation Strategies

Upgrade BIND to patched versions: 9.20.26, 9.21.24, or Supported Preview Edition 9.20.26-S1. No workarounds exist; patching is required. Ensure DNSSEC validation is enabled and monitor for unusual NSEC record processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13321. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart