SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-11331

HIGH · CVSS 7.5 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

BIND 9 versions 9.16.0 to 9.18.50, 9.20.0 to 9.20.24, and 9.21.0 to 9.21.23 are vulnerable to an attacker exploiting RPZ wildcard CNAME policies by crafting excessively long query names, potentially bypassing RPZ rules and causing unexpected software exits. This vulnerability poses a high risk, particularly for organizations relying on BIND 9 for DNS resolution and security policies. Administrators should prioritize patching affected versions to mitigate the risk of exploitation.

CVE
CVE-2026-11331
Severity
HIGH
CVSS
7.5
EPSS
0.42%

Original NVD Description

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.