Sceawere
Vulnerability Detail
CVE-2026-13321Updated Verified Sceawere Triage Sources: NVD / CISA KEV
BIND DNSSEC NSEC Validation Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 6h ago
- Vendor
- ISC
- Product
- BIND 9
- Attack Type
- CWE-346 Origin Validation Error
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-07-22T15:16:52.200Z",
"pubdate": "2026-07-22T15:16:52.200Z",
"executiveSummary": "An input validation vulnerability exists within the DNSSEC validation component of the BIND resolver.\nThe vulnerability specifically arises because the BIND resolver improperly accepts validly-signed NSEC records where the Next Domain Name field points outside of the authorized signer's zone.\nThis flaw impacts multiple BIND 9 branches, specifically versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.\nSuccessful exploitation of this issue allows an attacker to bypass critical DNSSEC validation checks, potentially leading to the acceptance of forged or malicious DNS data as authentic.\nThe risk implication involves compromised DNS integrity and potential redirection or spoofing attacks against clients relying on the affected resolver.\nExploitation requires the attacker to have the ability to supply or influence signed NSEC records that cross zone boundaries during resolution processes.",
"technicalDetails": "The vulnerability resides in the BIND resolver component responsible for parsing and validating DNSSEC NSEC records.\nThe root cause is an insufficient boundary check concerning the Next Domain Name field within NSEC resource records.\nWhen processing a validly-signed response, the resolver fails to verify whether the Next Domain Name properly resides within the administrative boundaries of the signer's zone.\nDuring the attack flow, a malicious or compromised authoritative name server provides a crafted NSEC record containing a Next Domain Name pointing outside the legitimate zone.\nThe vulnerable BIND resolver processes this record, incorrectly trusts the cryptographic signature, and bypasses standard zone closure validations.\nThis network-exposed flaw can be triggered remotely without authentication or high privilege requirements, provided the resolver queries the malicious zone controlled by the attacker.\nThe post-exploitation impact includes the potential subversion of DNS security guarantees, allowing attackers to manipulate negative caching or assertion mechanisms and compromise the resolution chain for targeted domains."
}