BIND9 RPZ wildcard CNAME NAMETOOLONG error 9.16-9.21
CVE-2026-11331 Published on July 22, 2026
Potential wildcard CNAME RPZ policy bypass
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software.
This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Vulnerability Analysis
CVE-2026-11331 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Improper Filtering of Special Elements
The software receives data from an upstream component, but does not filter or incorrectly filters special elements before sending it to a downstream component.
Products Associated with CVE-2026-11331
Want to know whenever a new CVE is published for ISC BIND? stack.watch will email you.
Affected Versions
ISC BIND 9:- Version 9.16.0, <= 9.18.50 is affected.
- Version 9.20.0, <= 9.20.24 is affected.
- Version 9.21.0, <= 9.21.23 is affected.
- Version 9.16.8-S1, <= 9.18.50-S1 is affected.
- Version 9.20.9-S1, <= 9.20.24-S1 is affected.