CVE-2026-19941 PUBLISHED

checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof

Assigner: isc
Reserved: 15.08.2026 Published: 16.09.2026 Updated: 16.09.2026

An inapplicable NSEC record may be accepted by a named resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 5.9

Product Status

Vendor ISC
Product BIND 9
Versions Default: unaffected
  • affected from 9.11.0 to 9.18.50 (incl.)
  • affected from 9.20.0 to 9.20.27 (incl.)
  • affected from 9.21.0 to 9.21.25 (incl.)
  • affected from 9.11.3-S1 to 9.18.50-S1 (incl.)
  • affected from 9.20.9-S1 to 9.20.27-S1 (incl.)

Exploits

This flaw was discovered in internal testing. We are not aware of any active exploits.

Workarounds

No workarounds known.

Solutions

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.

References

Problem Types

  • CWE-345 Insufficient Verification of Data Authenticity CWE

Impacts

  • An attacker at the same or an upstream zone name may be able to deny the existence of a wildcard mapping thus resulting in a cache poisoning attack.