Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-85501
NLnet Labs Unbound — Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0048 39.3 —
AFFECTED
Product Versions Fixed
Unbound unspecified —
TIMELINE
Sep 7 Reserved by NLnet Labs
Sep 16 Published (CNA: NLnet Labs)
Sep 23 RESCORED — CVE-2026-85501 (NLnet Labs Unbound). CVSS 5.3 → 7.5 (NVD).
Description
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 7, 2026 | Reserved | Reserved by NLnet Labs |
| September 16, 2026 | Published | Published (CNA: NLnet Labs) |
| September 23, 2026 | RESCORED | RESCORED — CVE-2026-85501 (NLnet Labs Unbound). CVSS 5.3 → 7.5 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| NLnet Labs | Unbound | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-85501 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.