VDB
GCVE-110-ISC-2026-13321
GCVE-110-ISC-2026-13321
Advisory Published
CVE: CVE-2026-13321
Title: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
Document version: 2.0
Posting date: 22 July 2026
Program impacted: BIND 9
Versions affected:
BIND
9.11.0 -> 9.18.50
9.20.0 -> 9.20.24
9.21.0 -> 9.21.23
BIND Supported Preview Edition
9.11.3-S1 -> 9.18.50-S1
9.20.9-S1 -> 9.20.24-S1
Severity: High
Exploitable: Remotely
Description:
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.
Impact:
...
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| ISC | BIND | — | — |
Aliases
References
Browse GCVE Records
75,792 records in the GCVE database · Updated August 2, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.