Two critical vulnerabilities in the BIND 9 are affecting organizations worldwide, creating risks for cache poisoning and DoS attacks.
See also: Cloudflare: DDoS attacks reach record rate of 7.3 Tbps

The vulnerabilities, identified as CVE-2025-40776 and CVE-2025-40777 , pose serious threats to the security of the DNS infrastructure , particularly for resolvers configured with certain advanced features. The first vulnerability, CVE-2025-40776 , targets BIND 9 resolvers that use EDNS Client Subnet (ECS) options and has a high severity score of 8.6 on the CVSS scale .
This “birthday attack” vulnerability only affects BIND Subscription Edition (-S) versions, specifically versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
The attack exploits the sending of ECS from resolvers to authorized servers, forcing them to perform queries that increase the probability of successfully guessing the origin port.
This vulnerability was discovered by Xiang Li from the AOSP Lab at Nankai University, and manages to bypass existing protection methods against birthday-type cache poisoning attacks.
See also: Citrix: NetScaler vulnerability used for DoS attacks
The vector score CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N indicates that the vulnerability can be exploited over a network, with significant impact on data integrity.

The CVE-2025-40777 vulnerability presents a different type of threat, allowing denial of service (DoS) attacks via assertion failures and has a CVSS score of 7.5.
The vulnerability affects BIND versions 9.20.0 through 9.20.10 and 9.21.0 through 9.21.9 , as well as their respective Supported Preview Editions .
Its activation occurs when resolvers are configured with the serve-stale-enable yes and stale-answer-client-timeout has a value of 0.
See also: PoC exploit released for Apache Tomcat DoS vulnerability
Cache poisoning and denial-of-service attacks can lead to misleading user routing (e.g., to malicious websites) or even total collapse of DNS-based services . This highlights the need for constant monitoring, configuration resilience, and, where possible, the use of techniques such as DNSSEC, which adds digital signatures to protect the authenticity of DNS responses.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
