CVE-2023-50387, known as KeyTrap, is a DNSSEC protocol denial-of-service vulnerability affecting validating DNS resolvers. An attacker can operate a DNS zone containing numerous or crafted DNSKEY and RRSIG records. During DNSSEC validation, protocol-required signature verification can require evaluation of combinations of these records, causing excessive CPU consumption. In PowerDNS Recursor, crafted DNSSEC records from an attacker-controlled zone can exhaust validation resources and disrupt DNS query processing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) for CVE-2023-50387 (KeyTrap), a vulnerability in DNSSEC validation that can be exploited to cause a denial-of-service (DoS) condition in DNS resolvers. The PoC sets up a local test environment using Docker Compose, with three main services: an attacker (for issuing DNS queries), a resolver (Unbound), and an authoritative DNS server (BIND9) configured with DNSSEC and a specially crafted zone file (a.test.zone/a.test.zone.signed) containing multiple colliding DNSSEC keys. The exploit works by sending DNS queries (e.g., for www.a.test or b.a.test) that trigger excessive cryptographic operations in the resolver, leading to timeouts and unresponsiveness. The repository includes configuration files for all services, DNSSEC keys, and a Python script (rrsig.py) for generating dummy RRSIG records. The PoC is intentionally limited for educational purposes and does not include scripts for generating colliding keys at scale. The main attack vector is network-based, targeting DNS resolvers that perform DNSSEC validation. The endpoints involved are the test DNS zone (a.test.), its subdomains, and the local Docker network IPs.
This repository is a proof-of-concept (PoC) demonstrating the generation and use of multiple DNSSEC keys with colliding key tags for the same domain (example.edu). The structure includes a set of directories containing key pairs (public and private) for the domain, all with the same key tag (34345) but different key material. The 'KeyGenerator.sh' script automates the generation of ECDSAP256SHA256 DNSSEC keys until a desired key tag is found, while 'KeySigGen.py' generates dummy RRSIG records for testing. The provided zone files ('example.edu.db' and 'example.edu.db.signed') show how these colliding keys can be inserted into a DNSSEC-signed zone. The README references the SEED Labs DNSSEC infrastructure, indicating this PoC is intended for educational or research use. The main exploit capability is to create a situation where multiple DNSSEC keys with the same key tag exist, which can be used to test or potentially exploit DNSSEC implementations that do not handle such collisions securely. The main endpoints are the DNS records for example.edu and its subdomains, as well as the associated IP addresses.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability covered by the referenced CentOS 7 local security advisory/plugin. The provided content does not describe its technical impact.
A vulnerability referenced by an AlmaLinux 9.2 local security-check plugin. The supplied content provides no technical details for this specific CVE.
A DNSSEC denial-of-service vulnerability family referenced for comparison; the content says the discussed issue matches the broader KeyTrap attack class but is a distinct mechanism.
Unknown
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.