A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-3592

CVE-2026-3592: BIND DNS Resolver DoS Vulnerability

CVE-2026-3592 is a denial of service vulnerability in BIND DNS resolvers that enables amplified resource exhaustion attacks through specially crafted zones. This article covers technical details, affected versions, and mitigation.

Published: May 21, 2026

CVE-2026-3592 Overview

CVE-2026-3592 is a resource exhaustion vulnerability in ISC BIND 9 resolvers. When a victim resolver queries a specially crafted authoritative zone, it consumes disproportionate CPU and memory resources. Attackers exploit this asymmetry to amplify resource consumption against recursive DNS infrastructure.

The flaw is categorized under [CWE-408] (Incorrect Behavior Order: Early Amplification). It affects long-supported branches of BIND 9, including both open-source and Subscription Edition (-S1) builds. No authentication or user interaction is required, and the attack is network-reachable.

Critical Impact

A remote, unauthenticated attacker controlling or influencing a queried zone can degrade resolver availability through amplified resource consumption, impacting DNS resolution for downstream clients.

Affected Products

  • ISC BIND 9 versions 9.11.0 through 9.16.50
  • ISC BIND 9 versions 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, and 9.21.0 through 9.21.21
  • ISC BIND 9 Subscription Edition: 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1

Discovery Timeline

  • 2026-05-20 - CVE-2026-3592 published to NVD
  • 2026-05-20 - Last updated in NVD database

Technical Details for CVE-2026-3592

Vulnerability Analysis

The vulnerability resides in how BIND 9 resolvers process responses from authoritative servers for certain zone constructions. Querying a maliciously crafted zone forces the resolver to perform disproportionate internal work relative to the query size. The result is amplified consumption of CPU, memory, or socket resources on the resolver host.

Because recursive resolvers serve many downstream clients, a sustained stream of queries that trigger this asymmetry degrades resolution for legitimate users. The attack vector requires no privileges or interaction, only the ability to induce a target resolver to query an attacker-controlled or attacker-influenced zone. Confidentiality and integrity are unaffected; the impact is limited to availability.

Root Cause

The defect is an algorithmic complexity issue in resolver processing logic. Specific zone configurations trigger work that scales unfavorably relative to input size. ISC tracks the issue under [CWE-408], reflecting that processing order and validation behavior allow amplification before resource limits engage.

Attack Vector

An attacker hosts or controls a zone constructed to maximize resolver-side processing cost. The attacker then causes a victim BIND resolver to query that zone, either directly through open recursion or indirectly by inducing client queries that the resolver must follow. Each query yields significant resource consumption on the resolver, enabling denial-of-service amplification with modest attacker bandwidth.

No verified public exploit code is available. Refer to the ISC CVE-2026-3592 Documentation for vendor technical details.

Detection Methods for CVE-2026-3592

Indicators of Compromise

  • Sustained spikes in named process CPU or memory consumption without a corresponding rise in legitimate client query volume.
  • Recursive query patterns concentrated on a small number of unusual or newly observed authoritative zones.
  • Growing resolver query queues, increased SERVFAIL rates, and elevated response latency for unrelated client traffic.

Detection Strategies

  • Enable BIND query logging and statistics channels, then baseline per-zone query distributions to flag anomalous concentrations.
  • Correlate resolver host telemetry (CPU, RSS, file descriptors) with outbound recursion patterns to identify resource amplification.
  • Alert on repeated recursive lookups to low-reputation or recently registered zones using passive DNS or threat intelligence feeds.

Monitoring Recommendations

  • Track BIND recursive-clients, tcp-clients, and memory counters via the statistics channel and forward metrics to a SIEM.
  • Monitor upstream and downstream DNS latency to detect resolver degradation before client-visible outages occur.
  • Capture and retain DNS query logs for forensic correlation when resource-exhaustion symptoms appear.

How to Mitigate CVE-2026-3592

Immediate Actions Required

  • Upgrade BIND 9 to a fixed release: 9.18.49, 9.20.23, or 9.21.22, available from the ISC BIND download site.
  • Subscription Edition users should obtain the corresponding -S1 build directly from ISC.
  • Restrict recursion to trusted clients using allow-recursion to reduce exposure from arbitrary external queriers.

Patch Information

ISC has released fixed versions BIND 9.18.49, BIND 9.20.23, and BIND 9.21.22. Operators on the end-of-life 9.16 branch should migrate to a supported release. Full advisory details are documented in the ISC CVE-2026-3592 knowledge base article.

Workarounds

  • Limit recursion scope with allow-recursion access control lists so only authorized internal clients can drive outbound queries.
  • Enforce per-client rate limits using fetches-per-server and fetches-per-zone to cap concurrent fetches against any single zone.
  • Deploy upstream DNS firewalls or Response Policy Zones (RPZ) to block resolution of known-malicious or attacker-controlled zones.
bash
# Configuration example: constrain recursion and per-zone fetches in named.conf
options {
    recursion yes;
    allow-recursion { 10.0.0.0/8; 192.168.0.0/16; };
    fetches-per-zone 200 drop;
    fetches-per-server 100;
    recursive-clients 1000;
};

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechBind

  • SeverityMEDIUM

  • CVSS Score5.3

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityLow
  • CWE References
  • CWE-408
  • Technical References
  • ISC BIND 9.18.49 Download

  • ISC BIND 9.20.23 Download

  • ISC BIND 9.21.22 Download

  • ISC CVE-2026-3592 Documentation
  • Related CVEs
  • CVE-2026-3039: BIND DNS Server DoS Vulnerability

  • CVE-2026-5950: BIND 9 Resolver DoS Vulnerability

  • CVE-2026-5946: BIND 9 DNS Denial of Service Vulnerability

  • CVE-2024-12705: BIND 9 DNS-over-HTTPS DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English