VDB
GCVE-110-ISC-2026-77692
GCVE-110-ISC-2026-77692
Advisory Published
CVE: CVE-2026-77692
Title: Unauthenticated remote crash of named via a single DoH SIG(0) request
Document version: 2.0
Posting date: 16 September 2026
Program impacted: BIND 9
Versions affected:
BIND
9.20.0 -> 9.20.27
9.21.0 -> 9.21.25
BIND Supported Preview Edition
9.20.9-S1 -> 9.20.27-S1
Severity: High
Exploitable: Remotely
Description:
An attacker can cause named to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the trans ...
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| ISC | BIND | — | — |
Aliases
Browse GCVE Records
395 records in the GCVE database · Updated September 17, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.