CVE-2026-5950General(isc / bind)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isc bind systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-606

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-05-21); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline10 mentions / 7d
01223Mentions · 2026-05-20: 2Mentions · 2026-05-21: 3Mentions · 2026-05-22: 1Mentions · 2026-05-25: 1Mentions · 2026-06-03: 1Mentions · 2026-06-15: 1Mentions · 2026-06-25: 1Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-06-15: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 3Technical Details · 2026-05-22: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-15: 105-2005-2105-2205-2506-0306-1506-25
Signal classification3 categories
General
440.0%
Disclosure
330.0%
Patch
330.0%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-05-202
General2
2026-05-213
Disclosure1Patch2
2026-05-221
Disclosure1
2026-05-251
Disclosure1
2026-06-031
General1
2026-06-151
Patch1
2026-06-251
General1
Full discourse10 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】BIND 9.xの脆弱性(再送信の無限ループの発生)について(CVE-2026-5950) - バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-05-21-bind9-vuln-resendloop.html

    Post summary

    The notice alerts about a BIND 9.x vulnerability (CVE-2026-5950) that causes an infinite resend loop and strongly advises users to upgrade, with no evidence of active exploitation or PoC availability.

    05061566
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    General

    https://kb.isc.org/docs/cve-2026-3039 https://kb.isc.org/docs/cve-2026-3592 https://kb.isc.org/docs/cve-2026-3593 https://kb.isc.org/docs/cve-2026-5946 https://kb.isc.org/docs/cve-2026-5947 https://kb.isc.org/docs/cve-2026-5950

    Post summary

    The provided text consists only of URLs to ISC‑Tinydns technical documentation, with no explicit detail about proofs of concept, exploitation methods, active attacks, patches, or technical specifics.

    03120377
    4.5K followersView on X
  • Yu F@fj_twt
    General

    CVE-2026-5950: Unbounded resend loop in BIND 9 resolver https://kb.isc.org/docs/cve-2026-5950

    Post summary

    The provided text briefly announces CVE‑2026‑5950 with a concise technical description and a link to the ISC knowledge base, but offers no PoC, exploit, or mitigation details.

    02110296
    1.5K followersView on X
  • offsite@offsitedark
    General

    The physical body exists at a less evolved plane only to verify one's existence in the universe... . . . . . . . . https://www.offsitedark.com/news/bind-resolver-loop-cve-2026-5950 https://t.co/Js0dNpaHlV

    Post summary

    The tweet offers a poetic line and a link to an article about CVE‑2026‑5950 without providing any further vulnerability details, PoC, or patch information.

    0003058
    1.2K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BINDに複数脆弱性、DNS運用者は更新確認を】 JVNは、BINDに複数の脆弱性が存在すると公表しました。 対象には CVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950 が含まれ、サービス運用妨害やメモリ破壊につながる可能性が示されています。 DNSは停止時の影響が広範囲に及ぶため、外部公開DNSだけでなく、内部リゾルバや委託先のDNS運用状況も確認が必要です。 日本の組織では、BINDのバージョン、namedの異常終了、SERVFAIL急増、DNS監視と冗長化の状態を週明けに確認したいところです。 #BIND #DNS #JVN #CVE #脆弱性対応 #インフラ運用 #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    JVN announced multiple new CVEs affecting BIND, noting potential service disruption and memory corruption, and urged DNS operators to verify updates and monitor operations.

    01020318
    3.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    JVNVU#99225456: ISC BINDにおける複数の脆弱性(2026年5月) https://jvn.jp/vu/JVNVU99225456/ "遠隔の攻撃者によって、サービス運用妨害(DoS)攻撃を引き起こされる(CVE-2026-3039、CVE-2026-3592、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950)" https://t.co/M7l9Giby22

    Post summary

    ISC BIND is reported to have multiple CVEs (CVE-2026-3039, 3592, 5946–5950) that enable remote attackers to perform DoS attacks.

    00001206
    3.5K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora shipped BIND 9.21.22 security fixes for six DNS vulnerabilities, including CVE-2026-5950 causing unbounded recursion loops, for Fedora 43 and 44 systems, Linuxsecurity reported. https://threatcluster.io/cluster/critical-dns-vulnerabilities-in-fedora-bind-92122-require-im-3ad374aa

    Post summary

    Fedora has released BIND 9.21.22 security patches addressing six DNS vulnerabilities, including CVE-2026-5950 which triggers unbounded recursion loops. The update mitigates the identified issues on Fedora 43 and 44.

    00000102
    330 followersView on X
  • iototsecnews@iototsecnews
    General

    BIND 9 の複数の脆弱性が FIX:サービス拒否 (DoS)/メモリ破損/リモート攻撃などの恐れ https://iototsecnews.jp/2026/05/27/bind-9-software-vulnerabilities-exposes-resolvers-and-authoritative-servers-to-remote-exploits/ BIND 9 に発生した一連の脆弱性は、 メモリ管理の不備/特定のクエリを処理する際のループ制御/リソースの制限不足などに起因するものである。脆弱性 CVE-2026-3593 では、DNS-over-HTTPS (DoH) 機能において、すでに解放されたメモリ領域に誤ってアクセスされる設計上の弱点が存在します。 また、CVE-2026-5950 では リゾルバの処理ロジックにおいて無限に処理が繰り返されてしまう不備があり、外部からの通信によりシステムリソースが枯渇し、サービス拒否を招く恐れがあります。ご利用のチームは、ご注意ください。 #BIND9 #CVE20263039 #CVE20263592 #CVE20265946 #CVE20265947 #Vulnerability

    Post summary

    The article outlines several BIND 9 CVEs, detailing memory‑management and processing flaws that could lead to DoS attacks, but it does not report active exploitation, offer patches, or provide PoC information.

    0000097
    491 followersView on X
  • Moselwal Digitalagentur GmbH@moselwal
    Disclosure

    CVE-2026-5950 — Unbounded Resend Loop im BIND-9-Resolver: warum DNS-Resilienz mehr ist als nur ein Patch in der Update-Welle https://moselwal.de/blog/cve-2026-5950-bind9-resolver-unbounded-resend-loop https://t.co/C3kfsC0hTO

    Post summary

    The tweet announces CVE‑2026‑5950—an unbounded resend loop flaw in BIND‑9—and points to a blog post for further information, presenting a new vulnerability disclosure without assertion of exploitation or patch details.

    0000060
    161 followersView on X
  • 珈琲好き@likecoffee
    Patch

    BIND 9.xの脆弱性(再送信の無限ループの発生)について(CVE-2026-5950)- バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-05-21-bind9-vuln-resendloop.html #%E6%8A%80%E8%A1%93%E7%B3%BB-%E8%B3%87%E6%96%99 #feedly

    Post summary

    The article announces CVE‑2026‑5950, a BIND 9.x infinite resend loop vulnerability, and urges users to upgrade to mitigate the risk.

    0000056
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more