cve-2026-3039

  1. CVE-2026-3039 BIND GSS-API TKEY DoS: Memory Exhaustion Risks for Windows DNS Estates

    CVE-2026-3039 is a high-severity remote denial-of-service flaw disclosed on May 20, 2026, in ISC BIND 9, where servers using GSS-API TKEY authentication can leak memory while processing maliciously crafted negotiation packets, eventually exhausting named and breaking DNS service. The bug is not...