CVE-2025-40778General

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-02-16); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-16: 4Mentions · 2026-03-26: 1PoC Mentioned / Linked · 2026-02-16: 1Patch / Workaround · 2026-02-16: 1Technical Details · 2026-02-16: 202-1603-26
Signal classification3 categories
General
360.0%
Disclosure
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-164
Disclosure1General2Patch1
2026-03-261
General1
Full discourse5 posts
  • Yasuhiro Morishita@OrangeMorishita
    General

    【自分用メモ】2025年10月に公開されたキャッシュポイズニング脆弱性の論文が出た。まだ読んでいない。 CVE-2025-40778(BIND)、CVE-2025-11411(Unbound)、CVE-2025-59023(PowerDNS Recursor) Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick Checking - NDSS Symposium https://www.ndss-symposium.org/ndss-paper/should-i-trust-you-rethinking-the-principle-of-zone-based-isolation-dns-bailiwick-checking/

    Post summary

    The memo notes the existence of three cache‑poisoning CVEs and references a related research paper, but it contains no technical, exploit, or mitigation details.

    15412113.3K
    4.4K followersView on X
  • transilienceai@transilienceai
    Patch

    @OrangeMorishita The paper proposes rethinking bailiwick rules for stricter validation. Public PoCs exist for CVE-2025-40778. 📜🔒 Vendors released fixes in late 2025: BIND: Update to 9.21.13 or later. #Patches #Mitigation

    Post summary

    Public PoCs exist for CVE-2025-40778, and vendors released a fix (BIND 9.21.13 or later).

    1000038
    313 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @OrangeMorishita These flaws allow cache injection or poisoning, potentially leading to domain hijacks or data forgery. CVE-2025-40778 (BIND 9 up to 9.21.12) allows BIND to accept records too leniently from answers, permitting forged cache data insertion. #CVE2025 #BIND

    Post summary

    CVE-2025-40778 is a BIND 9 cache poisoning flaw that permits forged DNS cache entries, potentially enabling domain hijack or data forgery.

    1000044
    313 followersView on X
  • transilienceai@transilienceai
    General

    "Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick Checking" is a research paper published in October 2025 that analyzes cache poisoning vulnerabilities in major DNS resolvers, including CVE-2025-40778 (BIND), CVE-2025-11411 (Unbound), and CVE-2025-59023 (PowerDNS Recursor). 📅🔍 It critiques the traditional zone-based isolation (DNS bailiwick checking) principle, arguing it fails under certain conditions, enabling attackers to inject forged records into caches. #DNS #Security

    Post summary

    A research paper critiques DNS bailiwick checking, analyzing cache poisoning vulnerabilities (CVE‑2025‑40778, CVE‑2025‑11411, CVE‑2025‑59023) and explaining how attackers can inject forged records into DNS caches.

    1000089
    313 followersView on X
  • iEM-Group@iem_security
    General

    iEM - Group / CVE - https://kb.isc.org/docs/cve-2025-40778 / https://check-host.net/check-report/3c7a1f75kef2 https://t.co/Xm5RPuMoPU

    Post summary

    The text only references a CVE ID and links to a knowledge‑base article without specific details about exploitation, patches, or technical aspects.

    00000223
    10 followersView on X

Explore more