← Vulnerability feed

Vulnerability record · CVE-2023-50387 · published 14 February 2024

CVE-2023-50387: DNSSEC KeyTrap flaw in DNS resolvers causes CPU exhaustion DoS

Redhat · Enterprise Linux

CVE-2023-50387, known as KeyTrap, is a flaw in DNSSEC validation logic where a zone containing many DNSKEY and RRSIG records forces resolvers to evaluate all algorithm combinations, consuming excessive CPU. It affects multiple DNS resolver implementations including BIND, Unbound, PowerDNS Recursor, Knot Resolver, dnsmasq, and Windows Server DNS. Because DNSSEC validation is widely deployed, a single crafted response can stall or take down a resolver, disrupting name resolution for all clients behind it.

7.5 CVSS 3.1 High EPSS 100% · top 0.1% CWE-770 · Allocation without limits
7.5CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
66References
17 Jun 2026Last modified by NVD

Description

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.5 and an EPSS near 1.0 indicate a remotely exploitable, high-likelihood denial-of-service flaw affecting widely deployed DNS resolvers, though it is not in KEV and causes availability loss only.

What it is

CVE-2023-50387, known as KeyTrap, is a flaw in DNSSEC validation logic where a zone containing many DNSKEY and RRSIG records forces resolvers to evaluate all algorithm combinations, consuming excessive CPU. It affects multiple DNS resolver implementations including BIND, Unbound, PowerDNS Recursor, Knot Resolver, dnsmasq, and Windows Server DNS. Because DNSSEC validation is widely deployed, a single crafted response can stall or take down a resolver, disrupting name resolution for all clients behind it.

Impact

An attacker can cause a denial of service by exhausting CPU on the validating resolver, making it unable to answer legitimate DNS queries. There is no confidentiality or integrity impact; the effect is availability loss for the resolver and its dependent services.

Attack surface

The flaw is reachable remotely over the network by sending one or more crafted DNSSEC responses to a validating resolver, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required; the attacker only needs to get the resolver to process a malicious response, for example by controlling or spoofing an authoritative zone.

Exploitation

CISA KEV does not list this CVE, but EPSS is extremely high at 0.99988 (99.984th percentile), indicating a strong likelihood of exploitation activity. References include vendor advisories and patches from Microsoft, ISC, NLnet Labs, PowerDNS, and Knot Resolver, but no public exploit code is tagged in the record.

What to do

  • Apply vendor patches for all affected resolvers: BIND, Unbound 1.19.1+, PowerDNS Recursor, Knot Resolver 5.7.1+, dnsmasq, and Windows Server DNS updates from Microsoft.
  • If immediate patching is not possible, reduce exposure by limiting DNSSEC validation to trusted zones or temporarily disabling validation where operationally acceptable.
  • Restrict recursive resolver access to trusted clients and networks to reduce the pool of attackers who can send crafted responses.
  • Monitor resolver CPU and query latency for anomalies and rate-limit or block sources generating excessive DNSSEC validation load.
  • Track vendor advisories for updated guidance, as the underlying protocol issue may require further changes beyond initial patches.

Detection

  • Monitor DNS resolver CPU utilization and query response latency for sustained spikes consistent with KeyTrap-style validation exhaustion.
  • Log and alert on DNSSEC responses containing unusually large numbers of DNSKEY and RRSIG records or algorithm combinations.
  • Baseline normal DNSSEC validation load per resolver and flag deviations, especially from a single source or zone.
  • Review resolver logs for timeouts, SERVFAIL spikes, or dropped queries that correlate with high CPU periods.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2024/02/16/2 Mailing List
http://www.openwall.com/lists/oss-security/2024/02/16/3 Mailing List
https://access.redhat.com/security/cve/CVE-2023-50387 Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1219823 Issue Tracking
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html Third Party Advisory
https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1 Patch
https://kb.isc.org/docs/cve-2023-50387 Third Party AdvisoryVDB Entry
https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html
https://lists.debian.org/debian-lts-announce/2024/05/msg00011.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4M
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVD Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPE
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCF Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH275
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJS Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6C
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWF
https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html Mailing ListThird Party Advisory
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-50387 PatchVendor Advisory
https://news.ycombinator.com/item?id=39367411 Third Party Advisory
https://news.ycombinator.com/item?id=39372384 Issue Tracking
https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/ Vendor Advisory
https://security.netapp.com/advisory/ntap-20240307-0007/
https://www.athene-center.de/aktuelles/key-trap Third Party Advisory
https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdf Technical DescriptionThird Party Advisory
https://www.isc.org/blogs/2024-bind-security-release/ Third Party Advisory
https://www.securityweek.com/keytrap-dns-attack-could-disable-large-parts-of-internet-researchers/ Press/Media CoverageThird Party Advisory
https://www.theregister.com/2024/02/13/dnssec_vulnerability_internet/ PatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2024/02/16/2 Mailing List
http://www.openwall.com/lists/oss-security/2024/02/16/3 Mailing List
https://access.redhat.com/security/cve/CVE-2023-50387 Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1219823 Issue Tracking
https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html Third Party Advisory
https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1 Patch
https://kb.isc.org/docs/cve-2023-50387 Third Party AdvisoryVDB Entry
https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html
https://lists.debian.org/debian-lts-announce/2024/05/msg00011.html
https://lists.debian.org/debian-lts-announce/2024/09/msg00001.html

Track CVE-2023-50387 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed10.0CVE-2020-1350Windows DNS Server improper input validation remote code executionWindows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication …KEVEPSS 97%analysed9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2023-50387), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.