CVE-2026-19666

Published Sep 16, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-19666 describes a vulnerability affecting BIND 9 resolvers configured to utilize `dns64`. If an authoritative server provides a specifically malformed answer, the `named` process of the resolver can terminate unexpectedly. This issue also applies to resolvers using `dns64` with the `break-dnssec yes` option enabled. The vulnerability impacts several versions of BIND 9, including 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, and 9.21.0 through 9.21.25, as well as specific versions of BIND 9.11.3-S1 through 9.18.50-S1 and 9.20.9-S1 through 9.20.27-S1. The Internet Systems Consortium (ISC) is the Common Vulnerabilities and Exposures (CVE) Numbering Authority (CNA) for this particular CVE.

Description
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Source
security-officer@isc.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security-officer@isc.org
CWE-416

Social media

Hype score
Not currently trending