# BIND 9 DoS Flaw Prompts IPA Patch Advisory

Published: 2026-01-22 · Severity: medium · Sectors: infrastructure, technology
Canonical: https://vorant.io/reports/d71c1451-1d19-510c-9715-970b4c035227/bind-9-dos-flaw-prompts-ipa-patch-advisory

> IPA warns of a denial-of-service vulnerability in ISC BIND 9 that could crash DNS servers, urging admins to upgrade to patched versions.

The Information-technology Promotion Agency (IPA) of Japan has issued an advisory regarding a denial-of-service vulnerability (CVE-2025-13878) in ISC BIND 9, a widely used DNS server software. If exploited, a remote attacker could cause the affected DNS server to abnormally terminate, potentially disrupting DNS resolution services.

No active exploitation has been observed at this time, but IPA cautions that attacks could emerge in the future given the public disclosure of the flaw. DNS server administrators are advised to upgrade to the patched versions released by ISC: BIND 9.18.44, 9.20.18, 9.21.17, and the Supported Preview Edition releases 9.18.44-S1 and 9.20.18-S1.

Given BIND's broad deployment as core internet infrastructure, unpatched instances represent an availability risk to organizations relying on it for DNS resolution. This is a standard patch advisory with no confirmed in-the-wild exploitation, warranting timely but not emergency remediation.

## Mentioned in this report

- Vulnerabilities: CVE-2025-13878

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260123.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/d71c1451-1d19-510c-9715-970b4c035227/bind-9-dos-flaw-prompts-ipa-patch-advisory.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
