logo

Just one bad packet can bring down a vulnerable DNS server thanks to DNSSEC

ID: 5939c9e4-0e04-5bfd-9aa2-cbbba65ab23e

STIX ID: report--5939c9e4-0e04-5bfd-9aa2-cbbba65ab23e

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-02-13

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

**Executive summary:** KeyTrap (CVE-2023-50387) is a long-standing DNSSEC validation design flaw that enables a single malicious DNS response to force DNSSEC-validating resolvers into extreme CPU exhaustion, potentially disabling resolution at Internet scale; researchers disclosed the issue privately, vendors released patches for major implementations (Unbound, BIND, PowerDNS, and public providers), and no active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.