{"id":"CVE-2023-50387","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-50387","summary":null,"details":"Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the \"KeyTrap\" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.","published":"2024-02-14T00:00:00Z","modified":"2026-08-12T14:51:46.856006Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.99995,"percentile":0.99988,"asOf":"2026-09-10"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2023-50387"},{"type":"WEB","url":"https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2023-50387"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00001.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00035.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/"},{"type":"WEB","url":"https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html"},{"type":"WEB","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-50387"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=39367411"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=39372384"},{"type":"WEB","url":"https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/"},{"type":"WEB","url":"https://www.athene-center.de/aktuelles/key-trap"},{"type":"WEB","url":"https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdf"},{"type":"WEB","url":"https://www.securityweek.com/keytrap-dns-attack-could-disable-large-parts-of-internet-researchers/"},{"type":"WEB","url":"https://www.theregister.com/2024/02/13/dnssec_vulnerability_internet/"},{"type":"ADVISORY","url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50387.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50387"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240307-0007/"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1219823"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/02/16/2"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/02/16/3"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00011.html"},{"type":"ARTICLE","url":"https://www.isc.org/blogs/2024-bind-security-release/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T14:51:46.856006Z"}}