CVE-2026-11331
HIGHCVE-2026-11331 is a high-severity (CVSS 7.5) CWE-790 vulnerability. No vendor fix is recorded yet; mitigation options are listed below.
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing.…
Exploitation Status
No confirmed exploitation observed yet
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-11331.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2026-11331 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 380,526 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Description
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2026-11331 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 10 | bind-32:9.18.33-15.el10_2.10 | RHSA-2026:55437 |
| Red Hat Enterprise Linux 8 | bind9.16-32:9.16.23-0.22.el8_10.12 | RHSA-2026:54509 |
| Red Hat Enterprise Linux 9 | bind-32:9.16.23-40.el9_8.8 | RHSA-2026:54510 |
| Red Hat Enterprise Linux 9 | bind9.18-32:9.18.29-14.el9_8.8 | RHSA-2026:55442 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | bind-32:9.16.23-18.el9_4.12 | RHSA-2026:57189 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | bind-32:9.16.23-31.el9_6.4 | RHSA-2026:55441 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202609011112-0 | RHSA-2026:62549 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202609031320-0 | RHSA-2026:65851 |
Frequently Asked Questions
Is CVE-2026-11331 in your dependencies?
Find it across , including transitive dependencies.