CVE-2026-33608: Incomplete domain name sanitization during
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33608?
CVE-2026-33608 is considered a high-severity vulnerability due to the potential disruption of the BIND backend service.
How do I fix CVE-2026-33608?
To fix CVE-2026-33608, ensure that your BIND installation is updated to a version that includes the relevant security patches.
What platforms are affected by CVE-2026-33608?
CVE-2026-33608 affects the Internet Systems Consortium BIND software specifically.
What impact does CVE-2026-33608 have on BIND?
CVE-2026-33608 can lead to an invalid configuration being saved, which can prevent the BIND backend from running after a restart.
Is there a workaround for CVE-2026-33608?
Currently, there is no recommended workaround for CVE-2026-33608 other than applying the appropriate updates to your BIND installation.