Back

HIGH

Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC

Published Sep 16, 2026

Description

Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.

Affected products

Remediation

Vendor solution

This issue is fixed starting with version 1.26.1

Red Hat statement

This Moderate flaw in Unbound can lead to a denial of service due to algorithmic complexity attacks on DNSSEC. An attacker can exploit this by serving malicious DNS zones, causing Unbound to consume excessive resources during DNSSEC validation, thereby degrading service availability. This affects Red Hat products utilizing Unbound for DNSSEC resolution, where the default configuration validates the additional section of DNS responses.

Red Hat mitigation

To mitigate implement hard caps on iterative processing loops and resource allocations per request. Apply rate limiting and set strict connection/processing timeouts to prevent a single complex operation from tying up worker threads. For this specific flaw, administrators can also configure system-level resource constraints (like CPU cgroups) for the service.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NLnet Labs
Published Sep 16, 2026
Updated Sep 16, 2026
Reserved Sep 7, 2026
CISA Vulnrichment
Updated Sep 16, 2026
NVD
Status Analyzed
Modified Sep 23, 2026
Red Hat
Severity Moderate
Public date Sep 16, 2026