CVE-2026-1519
HighAdvisory
Published 25 Mar 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.016
- 74th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 152
- of 17,781 indexed, latest versions
- Container images
- 126
- deployed by those charts
- Fix available
- 4 of 6
- affected packages
Red Hat Security Advisory: bind security update
Carried by container images the latest versions of 152 of 17,781 indexed charts deploy, on 126 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| bind9deb | 1:9.10.3.dfsg.P4-8ubuntu1.6, 1:9.10.3.dfsg.P4-8ubuntu1.9, 1:9.10.3.dfsg.P4-8ubuntu1.10, 1:9.10.3.dfsg.P4-8ubuntu1.11+40 more | 1:9.18.39-0ubuntu0.22.04.3, 1:9.18.39-0ubuntu0.24.04.3, 1:9.18.47-1~deb12u1, 1:9.20.11-1ubuntu2.2+1 more | 98 |
| bindrpm | 32:9.11.13-6.el8_2.4, 32:9.11.26-4.el8_4, 32:9.11.26-4.el8_4.1, 32:9.11.36-3.el8_6.5+8 more | 2:9.11.36-16.el8_10.7, 32:9.11.26-4.el8_4.9, 32:9.11.36-3.el8_6.12, 32:9.11.36-8.el8_8.9+3 more | 15 |
| bindapk | 9.18.33-r0, 9.18.35-r0, 9.18.37-r0, 9.18.39-r0+5 more | 9.18.47-r0, 9.20.21-r0 | 11 |
| bind9.18rpm | 32:9.18.29-5.el9_7.2 | 32:9.18.29-5.el9_7.4 | 1 |
| bind9-libsdeb | 1:9.11.19+dfsg-2.1ubuntu3 | no fix listed | 1 |
| isc-dhcpdeb | 4.3.5-3ubuntu7.1 | no fix listed | 1 |
- OSV records
- ALPINE-CVE-2026-1519DEBIAN-CVE-2026-1519RHSA-2026:15890RHSA-2026:16060RHSA-2026:16064RHSA-2026:25214RHSA-2026:7915RHSA-2026:8075RHSA-2026:8352RLSA-2026:8352UBUNTU-CVE-2026-1519
- Also known as
- DSA-6181-1, USN-8124-1
Charts affected
152 by stars
Container images carrying it
126 by charts deploying them
A fixed version is listed for 4 of the 6 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 3a4715b46aa2 | bind9 | no fix listed | 1 |
| ghcr.io/ | 54ebc1f90963 | bind9 | no fix listed | 1 |
| ghcr.io/ | e5571acd10ce | bind9 | 1:9.18.39-0ubuntu0.22.04.3 | 1 |
| ghcr.io/ | ef756c7d784b | bind9 | no fix listed | 1 |
| ghcr.io/ | c863aa9875fa | bind9 | no fix listed | 1 |
| ghcr.io/ | 61deadd1ec78 | bind9 | no fix listed | 1 |
| ghcr.io/ | 4273dfaf0295 | bind9 | 1:9.18.39-0ubuntu0.22.04.3 | 1 |
| ghcr.io/ | 0eb230e2381a | bind9 | 1:9.18.39-0ubuntu0.22.04.3 | 1 |
| ghcr.io/ | 4ea617c30397 | bind9 | no fix listed | 1 |
| ghcr.io/ | 6011182e3946 | bind9 | no fix listed | 1 |
| ghcr.io/ | 292b3614670f | bind9 | no fix listed | 1 |
| ghcr.io/ | 779858b5e11d | bind9 | no fix listed | 1 |
| ghcr.io/ | f52e66eff50b | bind9 | no fix listed | 1 |
| ghcr.io/ | 865ff4da5686 | bind9 | no fix listed | 1 |
| ghcr.io/ | ff2af53897e7 | bind9 | no fix listed | 1 |
| ghcr.io/ | fce820a03964 | bind | 9.20.21-r0 | 1 |
| ghcr.io/ | a56dfe91f5b1 | bind9 | 1:9.18.39-0ubuntu0.22.04.3 | 1 |
| public.ecr.aws/ | 849e235e2d3e | bind | 32:9.11.36-16.el8_10.7 | 1 |
| quay.io/ | 13aaae779248 | bind | 32:9.11.36-8.el8_8.9 | 1 |
| quay.io/ | a3b9a07648b6 | bind | 32:9.11.26-4.el8_4.9 | 1 |
| quay.io/ | 5f4572ef6d6f | bind9.18 | 32:9.18.29-5.el9_7.4 | 1 |
| quay.io/ | 3fead5702be7 | bind | 32:9.11.36-16.el8_10.7 | 1 |
| quay.io/ | 6722d5041b47 | bind | 32:9.11.36-16.el8_10.7 | 1 |
| quay.io/ | c241c971aef8 | bind | 32:9.11.36-3.el8_6.12 | 1 |
| quay.io/ | c6a934439421 | bind9 | no fix listed | 1 |
| quay.io/ | 6ba82beff18e | bind | 32:9.11.26-4.el8_4.9 | 1 |