Sploitus

CVE-2026-5950

2 known exploits for CVE-2026-5950

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

Isc Bind
< 9.18.49, 9.20.23, 9.21.21
CVSS 3.1
5.3 MEDIUM
EPSS
0.7% (49th percentile)
Weakness
CWE-606
NVD status
Analyzed
Published
2026-05-20

Fix

Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.49, 9.20.23, 9.21.22, 9.18.49-S1, or 9.20.23-S1.

Workaround

No workarounds known.

CVE-2026-5950 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-5950

Proof-of-concept code and exploit modules indexed by Sploitus