ISC disclosed CVE-2026-3039, a remote, unauthenticated denial-of-service flaw in BIND 9 that affects deployments using GSS-API TKEY authentication, such as Active Directory-integrated DNS and Kerberos-secured environments. The bug lets an attacker send repeated incomplete GSS-API tokens to DNS servers on port 53 during TKEY negotiation, causing gss_accept_sec_context() to allocate a security context that BIND neither preserves nor frees when the exchange remains incomplete. Because the leaked memory is allocated by the GSS library rather than BIND's own memory manager, the process can exhaust system memory and disrupt DNS resolution.
ISC rated the issue CVSS 7.5 and mapped it to CWE-771, noting that builds without GSSAPI support are not affected and that no workaround is available. Vulnerable releases span multiple supported branches, including 9.18.x, 9.20.x, and 9.21.x, while patched versions include 9.18.49, 9.20.23, and 9.21.22. The fix removes multi-round GSS-API negotiation support and adds RFC 3645-compliant checks for mutual authentication and integrity flags to prevent the context leak.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On May 20, 2026, ISC publicly disclosed CVE-2026-3039, a CVSS 7.5 denial-of-service flaw affecting GSS-API-enabled BIND 9 deployments. ISC said no workaround was available and released fixes in BIND 9.18.49, 9.20.23, 9.21.22, and corresponding supported preview editions.
ISC documented CVE-2026-3039 as a pre-authentication memory exhaustion vulnerability in BIND 9's GSS-API TKEY negotiation after a working reproducer was provided and the bug was confirmed. The issue allows unauthenticated attackers to trigger an unbounded memory leak that can lead to denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourcegitlab.isc.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.