---
id: CVE-2026-1519
title: >-
  If a BIND resolver is performing DNSSEC validation and encounters a
  maliciously crafted zone, the resolver may consume excessive CPU
summary: >-
  If a BIND resolver is performing DNSSEC validation and encounters a
  maliciously crafted zone, the resolver may consume excessive CPU.
  Authoritative-only servers are generally unaffected, although there are
  circumstances where authoritati…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-606
  - CWE-770
vendor: isc
product: bind
affected:
  - 'bind >= 9.11.0, <= 9.16.50'
  - 'bind >= 9.18.0, < 9.18.47'
  - 'bind >= 9.20.0, < 9.20.21'
  - 'bind >= 9.21.0, < 9.21.20'
patched:
  - bind 9.21.20
published: '2026-03-25'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T12:17:24.763'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1519'
references:
  - url: 'https://downloads.isc.org/isc/bind9/9.18.47'
    label: security-officer@isc.org
  - url: 'https://downloads.isc.org/isc/bind9/9.20.21'
    label: security-officer@isc.org
  - url: 'https://downloads.isc.org/isc/bind9/9.21.20'
    label: security-officer@isc.org
  - url: 'https://kb.isc.org/docs/cve-2026-1519'
    label: security-officer@isc.org
  - url: 'https://lists.debian.org/debian-lts-announce/2026/04/msg00008.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:11371'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11372'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:15890'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16060'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16064'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24500'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24851'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24934'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25083'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25171'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25214'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:29110'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:29863'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34048'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36610'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:40021'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43226'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60019'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:62549'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:65851'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6935'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:7915'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8075'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8155'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8312'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8352'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-1519'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2451305'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1519.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-1519'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1519'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-25T14:55:33.427270Z'
epss: 0.01599
epssPercentile: 0.74744
ingestedAt: '2026-07-03T14:03:36.906Z'
---

## Overview

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries).
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

## Affected

- `bind >= 9.11.0, <= 9.16.50`
- `bind >= 9.18.0, < 9.18.47`
- `bind >= 9.20.0, < 9.20.21`
- `bind >= 9.21.0, < 9.21.20`

## Remediation

Upgrade past the affected range:

- `bind 9.21.20`

## Vendor advisories

- **RHSA-2026:11372** · Red Hat · fixed in: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION), Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION) · released 2026-04-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:11372)
- **RHSA-2026:11371** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-04-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:11371)
- **RHSA-2026:34048** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:34048)
- **RHSA-2026:40021** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:40021)
- **RHSA-2026:36610** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:36610)
- **RHSA-2026:43226** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:43226)
- **RHSA-2026:62549** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:62549)
- **RHSA-2026:60019** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:60019)
- **RHSA-2026:29863** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:29863)
- **RHSA-2026:24851** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24851)
- **RHSA-2026:8312** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-04-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:8312)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1519.json)
- **RHSA-2026:65851** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65851)
