CVE-2026-5950
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
- Affected products
- Bind 9, Bind Server, Ibm Aix, Linuxmint, Ubuntu
- Isc Bind
- < 9.18.49, 9.20.23, 9.21.21
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 0.7% (49th percentile)
- Weakness
- CWE-606
- NVD status
- Analyzed
- Published
- 2026-05-20
Fix
Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.49, 9.20.23, 9.21.22, 9.18.49-S1, or 9.20.23-S1.
Workaround
No workarounds known.
CVE-2026-5950 at NVD
2 known exploits for CVE-2026-5950
Proof-of-concept code and exploit modules indexed by Sploitus