Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC
Published Sep 16, 2026
7.5
HIGHCVSS 3.1
EPSS 0.48%
Description
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.
Affected products
-
- Version 0StatusaffectedConstraints<1.26.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NLnet Labs | Unbound | unaffected |
|
No data.
Red Hat Hardened Images
unbound-main-1.26.1-1.hum1
Fixed · RHSA-2026:68590
Red Hat Enterprise Linux 10
unbound
Fix deferred
Red Hat Enterprise Linux 6
unbound
Out of support scope
Red Hat Enterprise Linux 7
unbound
Fix deferred
Red Hat Enterprise Linux 8
unbound
Fix deferred
Red Hat Enterprise Linux 9
unbound
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | unbound-main-1.26.1-1.hum1 | Fixed | RHSA-2026:68590 |
| Red Hat Enterprise Linux 10 | unbound | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | unbound | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | unbound | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | unbound | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | unbound | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
This issue is fixed starting with version 1.26.1
Red Hat statement
This Moderate flaw in Unbound can lead to a denial of service due to algorithmic complexity attacks on DNSSEC. An attacker can exploit this by serving malicious DNS zones, causing Unbound to consume excessive resources during DNSSEC validation, thereby degrading service availability. This affects Red Hat products utilizing Unbound for DNSSEC resolution, where the default configuration validates the additional section of DNS responses.
Red Hat mitigation
To mitigate implement hard caps on iterative processing loops and resource allocations per request. Apply rate limiting and set strict connection/processing timeouts to prevent a single complex operation from tying up worker threads. For this specific flaw, administrators can also configure system-level resource constraints (like CPU cgroups) for the service.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 16, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Sep–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.48% (0.00482) | 39.33th | v5 (v2026.06.15) |
| Sep 16, 2026 | 0.31% (0.00312) | 24.14th | v5 (v2026.06.15) |
References (5)
- https://access.redhat.com/security/cve/CVE-2026-85501 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2535057 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-85501
- https://www.cve.org/CVERecord?id=CVE-2026-85501
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-85501.txt vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-85501 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2535057 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-85501 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-85501 | ||
| https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-85501.txt | vendor-advisory |
Change history (0)
No recorded changes yet.