BIND9 RPZ wildcard CNAME NAMETOOLONG error 9.16-9.21
CVE-2026-11331 Published on July 22, 2026
Potential wildcard CNAME RPZ policy bypass
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software.
This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Vulnerability Analysis
CVE-2026-11331 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Improper Filtering of Special Elements
The software receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.
Products Associated with CVE-2026-11331
stack.watch emails you whenever new vulnerabilities are published in ISC BIND or Canonical Ubuntu Linux. Just hit a watch button to start following.
Affected Versions
ISC BIND 9:- Version 9.16.0, <= 9.18.50 is affected.
- Version 9.20.0, <= 9.20.24 is affected.
- Version 9.21.0, <= 9.21.23 is affected.
- Version 9.16.8-S1, <= 9.18.50-S1 is affected.
- Version 9.20.9-S1, <= 9.20.24-S1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.