CVE Vulnerabilities

CVE-2026-13321

Origin Validation Error

Published: Jul 22, 2026 | Modified: Jul 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.6 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The BIND resolver accepts validly-signed NSEC records where the Next Domain Name field points outside the signers zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 8RedHatbind9.16-32:9.16.23-0.22.el8_10.12*
Red Hat Enterprise Linux 8RedHatbind-32:9.11.36-16.el8_10.14*
Red Hat Enterprise Linux 8RedHatbind-32:9.11.36-16.el8_10.14*
Red Hat Enterprise Linux 9RedHatbind-32:9.16.23-40.el9_8.8*
Red Hat Hardened ImagesRedHatbind-main-9.20.26-0.1.hum1*

References