CVE-2026-13204

Summary

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Affected Software

VendorProductVersion RangeStatus
ISCBIND 99.11.0 <= 9.18.50affected
ISCBIND 99.20.0 <= 9.20.24affected
ISCBIND 99.21.0 <= 9.21.23affected
ISCBIND 99.11.3-S1 <= 9.18.50-S1affected
ISCBIND 99.20.9-S1 <= 9.20.24-S1affected

Weaknesses

  • CWE-617: CWE-617 Reachable Assertion

Workarounds

No workarounds known.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References