BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
CVE-2026-3592
MEDIUMNVD 5.35.3—
EchelonGraph scoreMEDIUM confidence
This medium-severity CVE scores 5.3 under NVD CVSS v3. EPSS exploit probability: 0.0%, top 96% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
Triggered by: NVD CVSS baseline
Sources: epss, nvd
5.3
- CVSS v3
- 5.3
- EG Score
- 5.3(medium)
- EPSS
- 3.9%
- KEV
- Not listed
Published
May 20, 2026
Last Modified
May 21, 2026
References (4)
- security-officer@ischttps://downloads.isc.org/isc/bind9/9.18.49
- security-officer@ischttps://downloads.isc.org/isc/bind9/9.20.23
- security-officer@ischttps://downloads.isc.org/isc/bind9/9.21.22
- security-officer@ischttps://kb.isc.org/docs/cve-2026-3592
Frequently asked(5)
What is CVE-2026-3592?
CVE-2026-3592 is a medium vulnerability published on May 20, 2026. BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0…
When was CVE-2026-3592 disclosed?
CVE-2026-3592 was first published in the National Vulnerability Database on May 20, 2026, with the most recent update on May 21, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-3592 actively exploited?
CVE-2026-3592 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 3.9% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2026-3592?
CVE-2026-3592 has a CVSS v3 base score of 5.3 (NVD).
How do I remediate CVE-2026-3592?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-3592, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-3592
Is Your Infrastructure Affected by CVE-2026-3592?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.