Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1837 articles · 155793 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-1519PATCHED
isc · bind

Excessive NSEC3 iterations cause high CPU load during insecure delegation validation

Description

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

Affected Products

VendorProductVersions
iscbind9.11.0, 9.18.0, 9.20.0, 9.21.0, 9.11.3-S1, 9.18.11-S1, 9.20.9-S1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
canonicalubuntu linuxcert_advisory90%
debiandebian linuxcert_advisory90%
fedorafedora linuxcert_advisory90%
ibmqradar siemcert_advisory90%
internet systems consortiumbindcert_advisory90%

References

  • https://kb.isc.org/docs/cve-2026-1519(vendor-advisory)
  • https://downloads.isc.org/isc/bind9/9.18.47(patch)
  • https://downloads.isc.org/isc/bind9/9.20.21(patch)
  • https://downloads.isc.org/isc/bind9/9.21.20(patch)

Related News (5 articles)

Tier B
BSI Advisories6h ago
[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR15d ago
Multiples vulnérabilités dans les produits VMware (11 mai 2026)
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[UPDATE] [mittel] Internet Systems Consortium BIND: Mehrere Schwachstellen
→ No new info (linked only)
Tier A
Microsoft MSRC58d ago
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
→ No new info (linked only)
Tier B
CERT-FR61d ago
Multiples vulnérabilités dans ISC BIND (26 mars 2026)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://kb.isc.org/docs/cve-2026-1519https://downloads.isc.org/isc/bind9/9.18.47https://downloads.isc.org/isc/bind9/9.20.21
CWECWE-606
PublishedMar 25, 2026
Last enriched54d ago
Trending Score53
Source articles5
Independent3
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-5946EXP
Invalid handling of CLASS != IN
Trending: 50
HIGHCVE-2026-5947EXP
SIG(0) validation during query flood may lead to undefined behavior
Trending: 47
MEDIUMCVE-2026-3592EXP
Amplification vulnerabilities via self-pointed glue records
Trending: 45
MEDIUMCVE-2026-5950EXP
Unbounded resend loop in BIND 9 resolver
Trending: 45
HIGHCVE-2026-3039EXP
BIND 9 server memory exhaustion during GSS-API TKEY negotiation
Trending: 45

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 25, 2026
Discovered by ZDM
Apr 1, 2026
Patch Available
Apr 13, 2026