CVE-2026-85501
published 2026-09-16CVE-2026-85501: Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.48%
39.1th percentile
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | < 1.26.1 | 1.26.1 |
| nlnetlabs | unbound | < 1.26.1 | 1.26.1 |
| openshift | ose-rhel-coreos-8 | — | — |
| openshift | ose-rhel-coreos-9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC
vendor_redhat·2026-09-16·CVSS 5.3
CVE-2026-85501 [MEDIUM] CWE-770 unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC
unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC
A flaw was found in Unbound. This vulnerability, termed 'ReTrap', allows a remote attacker to launch algorithmic complexity attacks on the Domain Name System Security Extensions (DNSSEC) validation process. By serving malicious zones or responses, an attacker can exploit various mechanisms, such as mismatched DNSKEY records, deeply nested domains, or excessive invalid NSEC records. Successful exploitation leads to a degradation of service, effectively causing a Denial of Service (DoS) for affected Unbound resolvers.
Package: openshift/ose-rhel-coreos-8 (Red Hat OpenShift Container Platform 4) - Fix deferred
Package: openshift/ose-rhel-coreos-9 (Red Hat OpenShift Container Platform 4) - Fix deferred
GHSA
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'.
ghsa_unreviewed·2026-09-16
CVE-2026-85501 [MEDIUM] CWE-770 Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'.
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where responses with excessive invalid NSEC reco
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-85501 unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC [fedora-all]
bugzilla·2026-09-21·CVSS 5.3
CVE-2026-85501 [MEDIUM] CVE-2026-85501 unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC [fedora-all]
CVE-2026-85501 unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses c
Bugzilla
CVE-2026-85501 unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC
bugzilla·2026-09-16·CVSS 5.3
CVE-2026-85501 [MEDIUM] CVE-2026-85501 unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC
CVE-2026-85501 unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results
Hackernews
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
blogs_hackernews·2026-09-17·CVSS 9.8
CVE-2026-81642 [CRITICAL] Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws. One of the eight, CVE-2026-82717 , is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code
2026-09-16
Published