{"id":"CVE-2026-5950","title":"An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry …","summary":"An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry …","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-606"],"vendor":"isc","product":"bind","affected":["bind >= 9.18.36, < 9.18.49","bind >= 9.20.8, < 9.20.23","bind >= 9.21.7, < 9.21.21"],"patched":["bind 9.21.21"],"published":"2026-05-20","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5950","references":[{"url":"https://downloads.isc.org/isc/bind9/9.18.49","label":"security-officer@isc.org"},{"url":"https://downloads.isc.org/isc/bind9/9.20.23","label":"security-officer@isc.org"},{"url":"https://downloads.isc.org/isc/bind9/9.21.22","label":"security-officer@isc.org"},{"url":"https://kb.isc.org/docs/cve-2026-5950","label":"security-officer@isc.org"}],"tags":["nvd","exploit-available"],"epss":0.0066,"epssPercentile":0.49774,"ingestedAt":"2026-07-23T12:17:54.932Z","exploits":{"github":1,"githubRepos":["https://github.com/billybaraja/cve-2026-5950-bind9-resolver-dos"],"checkedAt":"2026-09-21T15:29:50.009Z"},"exploitAvailable":true,"slug":"CVE-2026-5950","body":"## Overview\n\nAn unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions.\nThis issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.\n\n## Affected\n\n- `bind >= 9.18.36, < 9.18.49`\n- `bind >= 9.20.8, < 9.20.23`\n- `bind >= 9.21.7, < 9.21.21`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bind 9.21.21`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":5383,"id":"CVE-2026-5950","ts":1788887275112,"field":"exploit_available","old":"false","new":"true"},{"seq":4266,"id":"CVE-2026-5950","ts":1788886389759,"field":"exploit_available","old":"true","new":"false"},{"seq":3016,"id":"CVE-2026-5950","ts":1788883053375,"field":"exploit_available","old":"false","new":"true"},{"seq":2045,"id":"CVE-2026-5950","ts":1788882457574,"field":"exploit_available","old":"true","new":"false"},{"seq":1119,"id":"CVE-2026-5950","ts":1788881894559,"field":"exploit_available","old":"false","new":"true"}]}