VDB
GCVE-110-ISC-2026-11331
GCVE-110-ISC-2026-11331
Advisory Published
CVE: CVE-2026-11331
Title: Potential wildcard CNAME RPZ policy bypass
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND
9.16.0 -> 9.18.50
9.20.0 -> 9.20.24
9.21.0 -> 9.21.23
BIND Supported Preview Edition
9.16.8-S1 -> 9.18.50-S1
9.20.9-S1 -> 9.20.24-S1
Severity: High
Exploitable: Remotely
Description:
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLO ...
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| ISC | BIND | — | — |
Aliases
References
Browse GCVE Records
75,788 records in the GCVE database · Updated August 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.