PT-2026-93376 · Nlnet · Unbound
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions prior to 1.26.1
Description
Algorithmic complexity attacks, researched as 'ReTrap', can lead to service degradation when malicious zones are used. These attacks include TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism is exploited via responses with numerous mismatched DNSKEY, RRSIG, and DS records; DelegationTrap, which causes computational overhead during the iterative validation of the chain-of-trust for deeply nested domains; NsecTrap, which forces the resolver to validate excessive invalid NSEC records; and AdditionalTrap, where the default DNSSEC validation of the ADDITIONAL section is used to waste resources.
Recommendations
Update to a version newer than 1.26.0.
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound