Junglewise Threat Intelligence

CVE-2026-85501: NLnet Labs Unbound DNS complexity attacks via ReTrap

CVE-2026-85501 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Technologies: NLnet Labs Unbound. Vendors: NLnet Labs.

Executive brief

NLnet Labs Unbound is a DNS resolver that validates domain names using DNSSEC security. Attackers can craft malicious DNS responses that force the resolver to perform excessive computational work, causing slowdowns or denial of service to legitimate DNS queries. This affects any organization running Unbound 1.26.0 or earlier for DNS resolution.

Technical details

The vulnerability encompasses multiple DNSSEC algorithmic complexity attack vectors (TagTrap, DelegationTrap, NsecTrap, AdditionalTrap) that exploit resource-intensive validation logic in Unbound's DNSSEC processing. TagTrap abuses the triple(Zone, Algo, KeyTag) matching of DNSKEY and RRSIG records; DelegationTrap exploits iterative chain-of-trust validation for deeply nested domains; NsecTrap forces validation of excessive NSEC records; AdditionalTrap abuses optional validation of the DNS ADDITIONAL section. All attacks are network-reachable and require no authentication or user interaction—an attacker can send crafted DNS responses to trigger resource exhaustion. Unbound 1.26.1 patches all four attack vectors by introducing resource limits and throttling mechanisms. Versions prior to 1.26.1 are vulnerable.

Affected products

  • NLnet Labs Unbound up to and including 1.26.0

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Unbound 1.26.1 released with fixes; patch also available for 1.26.0

References

Related threats