Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-5950-bind9-resolver-dos — Defensive research notes for CVE-2026-5950, a BIND 9 resolver DoS vulnerability credited to Billy Baraja (BielraX). | Kitploit
Tools/GitHubGitHub/billybaraja/cve-2026-5950-bind9-resolver-dos
Defensive ToolsVulnerability AnalysisThreat IntelligenceLearning & EducationIncident ResponseDNS Analysis
GitHubbillybaraja/cve-2026-5950-bind9-resolver-dos

cve-2026-5950-bind9-resolver-dos

Defensive research notes for CVE-2026-5950, a BIND 9 resolver DoS vulnerability credited to Billy Baraja (BielraX).

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
1133 months agoNot yet reviewed
Share

CVE-2026-5950 - BIND 9 Resolver DoS

Research notes and defensive guidance for CVE-2026-5950, an unbounded resend loop vulnerability in the BIND 9 resolver state machine.

Overview

CVE-2026-5950 affects recursive BIND 9 resolvers. Under specific retry and bad-server handling conditions, a remote unauthenticated attacker may trigger repeated resend behavior that can cause severe resource exhaustion.

This repository is intentionally defensive. It does not publish exploit payloads or operational attack steps.

Key Facts

FieldValue
CVECVE-2026-5950
ProductISC BIND 9
ComponentResolver
WeaknessCWE-606: Unchecked Input for Loop Condition
SeverityMedium
CVSS v3.15.3
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
ImpactAvailability / resource exhaustion
ExploitableRemotely
AuthenticationNot required

Affected Versions

According to the ISC advisory, the affected ranges are:

BranchAffected versionsFixed version
BIND 9.189.18.36 through 9.18.489.18.49
BIND 9.209.20.8 through 9.20.229.20.23
BIND 9.219.21.7 through 9.21.219.21.22
BIND 9.18-S9.18.36-S1 through 9.18.48-S19.18.49-S1
BIND 9.20-S9.20.9-S1 through 9.20.22-S19.20.23-S1

Impact

The vulnerability can affect recursive resolver availability through resource exhaustion. ISC notes that resolvers are affected, while authoritative services are believed to be unaffected by this specific issue.

Defensive Checks

Use the helper script to classify a local BIND version:

python3 scripts/check_bind_version.py 9.20.22
python3 scripts/check_bind_version.py 9.20.23
python3 scripts/check_bind_version.py 9.18.48-S1

Expected output:

9.20.22: affected - upgrade to 9.20.23
9.20.23: not affected by the listed vulnerable range
9.18.48-S1: affected - upgrade to 9.18.49-S1

Recommended Remediation

Upgrade to the fixed release closest to the currently deployed branch:

  • 9.18.49
  • 9.20.23
  • 9.21.22
  • 9.18.49-S1
  • 9.20.23-S1

ISC states that there are no known workarounds in the public advisory.

Repository Contents

  • docs/advisory.md - structured advisory notes.
  • docs/detection.md - defensive version and environment checks.
  • scripts/check_bind_version.py - safe local version classifier.

Researcher Credit

The ISC advisory acknowledges Billy Baraja (BielraX) for bringing this vulnerability to ISC's attention.

References

  • ISC advisory: CVE-2026-5950
  • NVD: CVE-2026-5950
  • CVE record: CVE-2026-5950
Download Tool