8.6
CVSS V3
Status
Justification
Impact
CVE-2025-40776 affects only BIND Subscription Edition (-S) versions including 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1. The Wolfi bind package version 9.20.11-r1 is the open-source edition and is not affected by this vulnerability which specifically targets the commercial Subscription Edition with ECS (EDNS Client Subnet) configuration.
Status