CVE-2026-3593CRITICAL 7.4EPSS p72.4%
CVE-2026-3593CVE-2026-3593
isc / bind
Description
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1.
BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.
Scoring
| CVSS 3.1 | 7.4 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 1.54% probability of exploitation · percentile 72.4% · 2026-08-03T12:00:16Z |
| Published | 2026-05-20 |
| Last modified | 2026-07-24 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Use After Freecwe-416 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.