CVE-2023-50868, also known as the NSEC3 issue, is a resource-exhaustion vulnerability in the DNSSEC Closest Encloser Proof processing specified by RFC 5155. When RFC 9276 guidance is not followed, DNSSEC responses used in a random-subdomain attack can require a resolver to perform thousands of SHA-1 hash iterations. Crafted DNSSEC-related records in an attacker-controlled DNS zone can consequently cause excessive CPU consumption during validation and deny DNS resolution service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept toolkit for generating DNSSEC-signed zonefiles with custom NSEC3 parameters to reproduce and evaluate the NSEC3-encloser attack (CVE-2023-50868). The main components are Python scripts for generating DNSSEC keys (gen_keys.py) and zonefiles (gen_zones.py), a configuration system (config.json), and supporting libraries for DNSSEC and NSEC3 manipulation. The repository includes Dockerfiles and configuration for setting up test environments with NSD (authoritative server) and Unbound (resolver), allowing researchers to deploy the generated attack zones and observe resolver behavior. The exploit does not directly attack a target but provides the means to create malicious DNS zones that, when queried, can trigger excessive computation in vulnerable DNS resolvers, potentially leading to denial of service. The code is structured for flexibility, allowing users to specify various NSEC3 parameters and zone hierarchies. No hardcoded external network endpoints are present, but the system is designed to be run in isolated test environments using local IPs (127.0.0.1, 127.0.0.2).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DNSSEC NSEC3 algorithmic-complexity denial-of-service vulnerability. Crafted DNSSEC responses in random-subdomain attacks can force excessive SHA-1 hashing and consume CPU resources.
A vulnerability tracked as CVE-2023-50868, rated Important in this CentOS 8 local security-check plugin. The supplied CVSS v3 vector indicates a remotely exploitable, low-complexity, unauthenticated vulnerability with high availability impact.
A vulnerability covered by the referenced CentOS 7 local security advisory/plugin. The plugin rates it Important and states that exploits are available; its listed CVSS v3 vector indicates remotely reachable, unauthenticated availability impact.
A vulnerability referenced by an AlmaLinux 9.2 local security-check plugin. It has an availability-impact CVSS v3 vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, and the plugin states that exploits are available.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.