CVE-2026-10822
Last modified
CVE-2026-10822 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data.
Description
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ISC | BIND 9 | >= 9.18.0, <= 9.18.50; >= 9.20.0, <= 9.20.24; >= 9.21.0, <= 9.21.23; >= 9.18.11-S1, <= 9.18.50-S1; >= 9.20.9-S1, <= 9.20.24-S1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-10822?
How severe is CVE-2026-10822?
How do I fix CVE-2026-10822?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10816Arbitrary File Read (Unauthenticated) in NetScaler ADC and N…7.5
- CVE-2026-10817Insufficient input validation leading to memory overread in …7.5
- CVE-2026-10818The WPForms Pro plugin for WordPress is vulnerable to Arbitr…8.1
- CVE-2026-10819Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 1…6.5
- CVE-2026-1082The TITLE ANIMATOR plugin for WordPress is vulnerable to Cro…4.3
- CVE-2026-10820The Paid Membership Plugin, Ecommerce, User Registration For…8.1
- CVE-2026-10823The YMC Filter WordPress plugin before 3.11.3 does not prope…7.5
- CVE-2026-10824The Masteriyo LMS WordPress plugin before 2.2.1 does not pe…6.5
- CVE-2026-10825A denial-of-service vulnerability exists in the WebSocket AP…7.1
- CVE-2026-10827The Spectra Legacy WordPress plugin before 2.20.0 does not …3.5
- CVE-2026-10828A format string vulnerability has been found in the "alias" …6.9
- CVE-2026-10829A stack-based buffer overflow vulnerability has been found i…8.6
Are you affected by CVE-2026-10822?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
