CVE-2026-11605CWE-408

Unnecessary validation of DNSSEC signed records

High · published July 22, 2026

CVSS v3.1
7.5
EPSS
1%
Percentile
43.4
In the wild
Unconfirmed
What it is

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time.

This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00539 · 43.4th percentile
Weakness
CWE-408 · Incorrect Behavior Order: Early Amplification
Published
2026-07-22T14:11Z
EPSS history
Timeline
  • 22 JUL 14:11Z
    Unnecessary validation of DNSSEC signed records
    cvelistv5