Reachable Assertion Affecting bind package, versions [9.20.0,9.20.21)[9.21.0,9.21.20)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.58% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-BIND-15812206
  • published29 Mar 2026
  • disclosed25 Mar 2026
  • creditUnknown

Introduced: 25 Mar 2026

CVE-2026-3119  (opens in a new tab)
CWE-617  (opens in a new tab)

How to fix?

Upgrade bind to version 9.20.21, 9.21.20 or higher.

Overview

Affected versions of this package are vulnerable to Reachable Assertion in the named process when an attacker with a valid Transaction Signature (TSIG) key sends a specially crafted query containing a TKEY record. An attacker can cause the DNS service to crash by exploiting this flaw remotely with authenticated access. This is only exploitable if the attacker possesses a valid TSIG key configured on the server.

Workaround

This vulnerability can be mitigated by restricting access to the named service to trusted networks and clients, disabling TSIG keys if not required, or ensuring TSIG keys are securely managed and only distributed to authorized clients.

CVSS Base Scores

version 4.0
version 3.1