Impact
The vulnerability, termed 'ReTrap', exploits algorithmic complexity weaknesses in DNSSEC processing. Attackers can craft malicious zones that trigger excessive validation work for DNSKEY, RRSIG, DS, and NSEC records, leading to resource exhaustion on the resolver. This degrades service availability but does not leak sensitive data. The weakness corresponds to CWE‑770, which involves excessive resource consumption.
Affected Systems
NLnet Labs Unbound versions up to and including 1.26.0 are affected. The vulnerability is specific to that product and does not extend to earlier or later releases beyond 1.26.0.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available, suggesting no known widespread exploitation yet, and the issue is not listed in the CISA KEV catalog. However, the attack requires only DNS responses from malicious zones, making it remotely exploitable by anyone who can influence DNS traffic. The internal policy of Unbound to validate the additional section by default expands the attack surface, meaning that a domain administrator could easily cause a denial of service without modifying client applications.
OpenCVE Enrichment