CVE-2026-13204

Published Jul 22, 2026

Last updated 2 months ago

CVSS high 7.5
Dns
Port (53)

Overview

Description
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Source
security-officer@isc.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security-officer@isc.org
CWE-617

Social media

Hype score
Not currently trending
  1. RHSA-2026:54509 - bind9.16 security update (RHEL8) Security Fix(es): - CVE-2026-11331 - CVE-2026-13321 - CVE-2026-11622 - CVE-2026-11721 - CVE-2026-13204 - CVE-2026-10723 https://t.co/kOxtrR4DW5

    @makopicut

    14 Aug 2026

    65 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  2. ⚠️ Vulnerabilidades en productos ISC ❗ CVE-2026-13321 ❗ CVE-2026-13204 ❗ CVE-2026-12617 ➡️ Más info: https://t.co/Ft51udnS7J https://t.co/F9ZBhRX5OR

    @CERTpy

    3 Aug 2026

    182 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 【自分用メモ】BIND 9の脆弱性(High: CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, Medium: CVE-2026-10723, CVE-2026-10822)と修正バージョン(9.20.26, 9.21.24) https://t.co/W42kxTrGcC

    @OrangeMorishita

    23 Jul 2026

    840 Impressions

    2 Retweets

    8 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. BIND 9の脆弱性(High: CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321, Medium: CVE-2026-10723, CVE-2026-10822) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://t.co/E6Dlb6UAh9

    @omokazuki

    22 Jul 2026

    282 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨*CVE* CVE-2026-13204 If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unex… https://t.co/EXRvFvHmhD ----- Traducción: CVE-2026-13204 Si … https://t.co/utmtNg

    @infoflowcloud

    22 Jul 2026

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes