BIND 9 Update Patches 14 Flaws, Including Unauthenticated DoH Crash
ISC releases BIND 9.20.29 and 9.21.26 to address a critical denial-of-service vulnerability in DNS-over-HTTPS handling and 13 other security issues.

Key Takeaways
- BIND 9.20.29 and 9.21.26 fix fourteen security flaws, including a critical unauthenticated DoH crash vulnerability.
- The DoH vulnerability can be triggered by a single request with an invalid SIG record, crashing the 'named' process.
- All BIND servers that answer DNS-over-HTTPS queries are affected.
- No CVE identifiers were provided in the initial disclosure.
- Administrators should upgrade to the patched versions as soon as possible.
Quick answers
- What happened?
- The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws, including a critical vulnerability that allows an unauthenticated attacker to crash the 'named' process via a single specially crafted DNS-over-HTTPS (DoH) request. The update addresses all disclosed flaws, and administrators are urged to upgrade promptly.
- Which products are affected?
- BIND 9
- What should defenders do?
- Upgrade to BIND 9.20.29 or 9.21.26 immediately. If immediate patching is not possible, consider disabling DNS-over-HTTPS temporarily or restricting access to trusted clients. Monitor ISC advisories for further details.
On September 16, 2026, the Internet Systems Consortium (ISC) disclosed fourteen security flaws affecting BIND 9, its widely used open-source DNS server software. The following day, ISC released BIND 9.20.29 and 9.21.26 to remediate these vulnerabilities. Among the most severe is a flaw in the DNS-over-HTTPS (DoH) implementation that allows a remote, unauthenticated attacker to crash the 'named' process with a single request containing an invalid SIG record. This denial-of-service (DoS) vulnerability affects any BIND server that answers DoH queries. The remaining thirteen flaws have not been fully detailed in the public disclosure, but they are addressed by the same update. ISC recommends that all BIND operators upgrade to the patched versions immediately to mitigate potential exploitation. The advisory does not provide CVE identifiers for the flaws, and no active exploitation has been reported at the time of publication.
Security Details
A remote unauthenticated attacker can exploit the DoH vulnerability by sending a single specially crafted request containing an invalid SIG record to a BIND server that answers DNS-over-HTTPS queries. This causes the 'named' process to crash, resulting in a denial of service. The other thirteen flaws are not detailed in the public disclosure, but they are addressed by the same update.
Affected products
BIND 9
Mitigation
Upgrade to BIND 9.20.29 or 9.21.26 immediately. If immediate patching is not possible, consider disabling DNS-over-HTTPS temporarily or restricting access to trusted clients. Monitor ISC advisories for further details.
Sources
The Hacker News
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
Sep 17, 2026 · 08:00
Original link
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



