It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
Conclusion & alert: CVE-2024-11187 is rated Moderate Risk (61.2/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.18%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-28 | 4.07% | 4.18% | +0.11% |
| 2 | 2026-05-23 | 3.06% | 4.07% | +1.01% |
| 3 | 2026-05-22 | — | 3.06% | — |
Full EPSS history (33 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2024-11187: 1 source package rows (bind); 6 state rows across 6 repos (3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 6, open 0. | https://security.alpinelinux.org/vuln/CVE-2024-11187 |
debian
|
not yet assigned | CVE-2024-11187 not yet assigned priority: Debian including 1 source packages (bind9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-11187 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2024-11187 |
suse
|
high | CVE-2024-11187 severity important: SUSE including 381 source package names (5.0.3.7.16.1:bind-utils-9.18.33-150600.3.6.1, 5.1.0.6.40:bind-utils-9.20.9-150700.3.3.1, …), 1093 product×package rows across 271 product lines (Container suse/bind, Container suse/manager/5.0/x86_64/server, … (271 product lines)): Fixed 871, Known Affected 221, Known Not Affected 1. | https://www.suse.com/security/cve/CVE-2024-11187/ |
ubuntu
|
medium | CVE-2024-11187 medium priority: Ubuntu including 3 source packages (bind9, bind9-libs, isc-dhcp), 27 status rows across 10 suites (bionic, focal, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 7, released 7, not-affected 6, DNE 4, ignored 3. | https://ubuntu.com/security/CVE-2024-11187 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||