CVE-2026-3104Patch(isc / bind)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isc bind systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-772CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-03-25); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-03-25: 3Mentions · 2026-03-26: 2Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-04-01: 1Patch / Workaround · 2026-03-25: 2Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-28: 1Technical Details · 2026-04-01: 103-2503-2603-2703-2804-01
Signal classification3 categories
Patch
666.7%
General
222.2%
Disclosure
111.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-253
General1Patch2
2026-03-262
Disclosure1Patch1
2026-03-272
General1Patch1
2026-03-281
Patch1
2026-04-011
Patch1
Full discourse9 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】(緊急)BIND 9.20.xの脆弱性(メモリリークの発生)について(CVE-2026-3104) - BIND 9.20系列のみが対象、バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-03-26-bind9-vuln-noexist.html

    Post summary

    An emergency advisory warns of a memory‑leak vulnerability (CVE‑2026‑3104) affecting BIND 9.20.x and strongly urges users to upgrade to a patched version.

    0301121.0K
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    【自分用メモ】今回は4件。 CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation https://kb.isc.org/docs/cve-2026-1519 CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence https://kb.isc.org/docs/cve-2026-3104 CVE-2026-3119: Authenticated query containing a TKEY record may cause named to terminate unexpectedly https://kb.isc.org/docs/cve-2026-3119 CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass https://kb.isc.org/docs/cve-2026-3591

    Post summary

    The memo lists four newly disclosed DNS-related CVEs with concise technical details, but provides no evidence of exploitation, patches, or mitigations.

    042711.3K
    4.4K followersView on X
  • Kazuki Omo@omokazuki
    Patch

    SIOSセキュリティブログを更新しました。 BIND 9の脆弱性(High: CVE-2026-1519, CVE-2026-3104, Medium: CVE-2026-3119, CVE-2026-3591)と9.18.47, 9.20.21, 9.21.20のリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://security.sios.jp/vulnerability/bind-security-vulnerability-20260326/

    Post summary

    SIOS Security’s blog posts an update for BIND 9, releasing multiple patched versions that address several high‑ and medium‑severity CVEs, without mentioning PoC or active exploitation.

    03033877
    360 followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    4 CVEs fixed in BIND 9 https://www.openwall.com/lists/oss-security/2026/03/25/7 CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence + next tweet

    Post summary

    Announces that four CVEs have been fixed in BIND 9, providing brief technical details for two, and indicates a patch is available.

    11060545
    4.4K followersView on X
  • HostingTech@HostingTechNet
    Patch

    BIND Patch Vulnerabilities CVE-2026-3104 https://hostingtech.net/bind-patch-cve-2026-3104/ via @HostingTech https://t.co/7ntb1od1Of

    Post summary

    The tweet highlights a BIND vulnerability (CVE-2026-3104) and links to a resource that likely details the necessary patch, without providing PoC or exploit information.

    02030124
    121 followersView on X
  • Toshifumi Sakaguchi@siskrn
    General

    NSEC3の負荷問題とかTKEYとか。   https://kb.isc.org/docs/cve-2026-1519   https://kb.isc.org/docs/cve-2026-3104   https://kb.isc.org/docs/cve-2026-3119   https://kb.isc.org/docs/cve-2026-3591

    Post summary

    The post merely lists four CVE references with no additional context or details.

    01040201
    259 followersView on X
  • CCB Alert@CCBalert
    Patch

    Two High-Severity DoS vulnerabilities in ISC #BIND9 DNS resolvers. #CVE-2026-3104 & #CVE-2026-1519 CVSS: 7.5. Memory leak & CPU exhaustion can take down your DNS infrastructure! Read our advisory https://ccb.belgium.be/advisories/warning-isc-bind-9-dns-vulnerabilities-patch-immediately. #Patch #Patch #Patch

    Post summary

    The post warns of two severe DoS vulnerabilities (CVE-2026-3104 & CVE-2026-1519) affecting ISC BIND9 DNS resolvers, emphasizing the need for immediate patching.

    00010265
    7.2K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3104 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3104 #CVE-2026-3104 #CVE #High  #CyberSecurity #InfoSec https://t.co/xfuBC9da45

    Post summary

    A brief CVE alert noting CVE‑2026‑3104 with a severity score of 7.5 and a link to the NVD page; no other technical or exploit information provided.

    0000030
    123 followersView on X
  • IT関連サイト記事@itit7777
    Patch

    IT関連サイト記事が更新されました!記事はこちらから⇒ BIND 9の脆弱性(High: CVE-2026-1519, CVE-2026-3104, Medium: CVE-2026-3119, CVE-2026-3591)と9.18.47, 9.20.21, 9.21.20のリリース https://security.sios.jp/vulnerability/bind-security-vulnerability-20260326/

    Post summary

    The article announces BIND 9 vulnerabilities (CVE‑2026‑1519, 3104, 3119, 3591) and the release of patches 9.18.47, 9.20.21, 9.21.20 to remediate them.

    0000065
    448 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more