CVE-2026-81736
HIGHDescription
If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Is your site exposed to CVE-2026-81736?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-81736? +
How severe is CVE-2026-81736? +
How do I check if I'm vulnerable to CVE-2026-81736? +
Related Vulnerabilities
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to …
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to …
The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could …
A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This …
Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the …