ISC disclosed CVE-2026-3593, a heap use-after-free flaw in BIND 9's DNS-over-HTTPS implementation that can be triggered remotely without authentication by flooding a DoH endpoint with crafted HTTP/2 SETTINGS frames while a response is being written. The bug occurs in server_read_callback, where data is read from socket->h2->wbuf after the associated ns_client_t memory has already been freed through http_writecb and isc_nmhandle_detach, creating a race condition in affected DoH deployments.
Successful exploitation can crash the named process and cause denial of service, and ISC's issue report says freed heap data may also be copied into HTTP/2 response data and returned to the attacker over TLS, creating an information disclosure risk. The vulnerability affects BIND 9 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and Supported Preview Edition 9.20.9 S1 through 9.20.22 S1 when DoH is enabled; non-DoH configurations are not affected. Fixes are available in 9.20.23, 9.21.22, and 9.20.23 S1, and the issue is tracked as CWE-416 with a CVSS 7.4 score after an earlier code-execution claim was withdrawn.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The ISC GitLab reference explicitly states the vulnerability was publicly disclosed on 2026-05-20. ZeroPath also reports affected versions and available fixed releases for BIND 9 DoH deployments.
ZeroPath states the issue was reported to ISC by Naresh Kandula Parmar. The content does not provide a specific date for when the report was submitted.
An ISC GitLab issue describes CVE-2026-3593 as a heap use-after-free in BIND 9 DNS-over-HTTPS triggered by crafted HTTP/2 SETTINGS frames, with potential information disclosure and denial of service. The issue publication date is explicitly shown as 2026-02-18.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcegitlab.isc.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.