---
id: CVE-2026-85501
title: >-
  Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have
  been researched under the term 'ReTrap'
summary: >-
  Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have
  been researched under the term 'ReTrap'. These result in degradation of
  service when malicious zones are used to serve the algorithmic complexity
  vulnerabiliti…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
vendor: NLnet Labs
product: Unbound
affected:
  - Unbound < 1.26.1
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:41:10.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85501'
references:
  - url: 'https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-85501.txt'
    label: sep@nlnetlabs.nl
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85501.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-85501'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2535057'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-85501'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85501'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68590'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-16T14:10:48.623819Z'
ingestedAt: '2026-09-16T08:52:29.596Z'
epss: 0.00312
epssPercentile: 0.24281
patched:
  - hardened_images
---

## Overview

Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-85501.json)
- **RHSA-2026:68590** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68590)
