# CVE-2026-3593

> A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.

- **CVSS:** 7.4 (HIGH)
- **EPSS:** 0.0%
- **CWE:** CWE-416

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-3593
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
