Predictable from Observable State Affecting bind package, versions [,9.18.41)[,9.20.15)[,9.21.14)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.02% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-BIND-13703826
  • published24 Oct 2025
  • disclosed22 Oct 2025
  • creditAmit Klein, Omer Ben Simhon

Introduced: 22 Oct 2025

NewCVE-2025-40780  (opens in a new tab)
CWE-341  (opens in a new tab)

How to fix?

Upgrade bind to version 9.18.41, 9.20.15, 9.21.14 or higher.

Overview

Affected versions of this package are vulnerable to Predictable from Observable State due to the weakness in the Pseudo Random Number Generator (PRNG) used for selecting UDP source ports and DNS query IDs. An attacker can compromise the integrity of the resolver cache by predicting these values and injecting spoofed DNS responses through network-level spoofing and precise timing.

##Workaround

This vulnerability can be mitigated by restricting recursive queries to trusted or internal networks, applying rate limiting or firewall rules to prevent excessive requests, enabling DNSSEC validation to reject forged records, isolating recursive resolvers from authoritative servers, and actively monitoring for cache anomalies.

CVSS Base Scores

version 4.0
version 3.1