CVE•Published 2026-05-20•Modified 2026-07-23•0 articles on news•5 live references•NVD data
CVE-2026-5950Isc · Bind
Vulnerability data via NVD (ingested)
CVSS v3.1
5.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS percentile
42
Exploit Prediction Scoring System · top 58% of all CVEs
Weaknesses (CWE)
Description
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
Timeline
Published 2026-05-20
Modified 2026-07-23
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-5950Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Isc Bind"All exposed Isc Bind instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Bind"HTTP body or banner mentions "Bind" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-5950Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-5950Censys host search filtered to this CVE id.
grep.app
CVE-2026-5950Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-5950GitHub code search for direct mentions.
Google dork
"CVE-2026-5950" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (7)
CVE-2026-59507 repos
nomi-sec/PoC-in-GitHubunknown
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
Zeyad-Azima/Offensive-Resourcesunknown
A Huge Learning Resources with Labs For Offensive Security Players
mooyoul/awesome-starsunknown
A curated list of my GitHub stars
oslook/n8n-workflowsunknown
4200 + Workflow Automation Templates are Grouped by Categories/Services for easy navigation
ARPSyndicate/euvd-scoresunknown
VEDAS Score Aggregator for EUVDs
billybaraja/cve-2026-5950-bind9-resolver-dosPython
Defensive research notes for CVE-2026-5950, a BIND 9 resolver DoS vulnerability credited to Billy Baraja (BielraX).
Darkham42/starsunknown
We haven't classified any articles referencing CVE-2026-5950 yet. The external references above still apply.