logo

KeyTrap attack: Internet access disrupted with one DNS packet

ID: 6fc2d253-a7ee-5b46-bced-6a5ecfcb7de8

STIX ID: report--6fc2d253-a7ee-5b46-bced-6a5ecfcb7de8

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

KeyTrap (CVE-2023-50387) is a decades-old DNSSEC design flaw that enables algorithmic complexity attacks: a single crafted DNS packet can force resolvers to process excessive cryptographic keys and signatures (up to a ~2 million× increase in CPU instructions), stalling DNS resolution for between roughly one minute and many hours. Discovered and disclosed by ATHENE researchers, the issue affects many popular DNS implementations and services; major providers have applied mitigations, but researchers warn addressing the root cause may require rethinking DNSSEC validation design.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.