Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-50387

78
FAUCET Score

CVE-2023-50387, dubbed "KeyTrap," is a denial-of-service vulnerability affecting various DNSSEC implementations, including those from ISC, Microsoft, and Red Hat. It exploits a design flaw in the DNSSEC protocol where an attacker can craft DNSSEC responses that force DNS resolvers to perform extensive, CPU-intensive computations by evaluating all combinations of numerous DNSKEY and RRSIG records. This unauthenticated, low-complexity attack has a CVSS score of 7.5 (High), indicating a significant potential for service disruption. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered substantial community attention and media coverage, highlighting its potential to severely impact internet access.

Impacted Technologies

VendorProductVersion(s)CPE
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
r2CPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
100.00%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 1.0000 is in the 100th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (72)

denopatch availablevia llm_extracted
View patch
keraspatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 (Server Core installation)Fixed in: 6.2.9200.24710
View patch
microsoftpatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2 (Server Core installation)Fixed in: 6.3.9600.21813
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2Fixed in: 6.3.9600.21813
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019Fixed in: 10.0.17763.5458
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019 (Server Core installation)Fixed in: 10.0.17763.5458
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022Fixed in: 10.0.20348.2322
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022 (Server Core installation)Fixed in: 10.0.20348.2322
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022, 23H2 Edition (Server Core installation)Fixed in: 10.0.25398.709
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016Fixed in: 10.0.14393.6709
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016 (Server Core installation)Fixed in: 10.0.14393.6709
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for x64-based Systems Service Pack 1Fixed in: 6.1.7601.26961
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)Fixed in: 6.1.7601.26961
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012Fixed in: 6.2.9200.24710
View patch
nessuspatch availablevia llm_extracted
Fixed in: 9.18.23-S1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: unbound-0:1.7.3-12.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: unbound-0:1.7.3-15.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: bind-32:9.11.26-4.el8_4.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: dhcp-12:4.3.6-44.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: dnsmasq-0:2.79-15.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: unbound-0:1.7.3-15.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: bind-32:9.11.26-4.el8_4.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: dhcp-12:4.3.6-44.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: dnsmasq-0:2.79-15.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: unbound-0:1.7.3-15.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: bind-32:9.11.26-4.el8_4.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: dhcp-12:4.3.6-44.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: dnsmasq-0:2.79-15.el8_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: dnsmasq-0:2.79-21.el8_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: bind9.16-32:9.16.23-0.7.el8_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: unbound-0:1.7.3-17.el8_6.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: bind-32:9.11.36-3.el8_6.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: dhcp-12:4.3.6-47.el8_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: unbound-0:1.16.2-5.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: dnsmasq-0:2.79-26.el8_8.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: bind9.16-32:9.16.23-0.14.el8_8.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: bind-32:9.11.36-8.el8_8.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: dhcp-12:4.3.6-49.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: unbound-0:1.16.2-3.el9_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dnsmasq-0:2.85-14.el9_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: bind-32:9.16.23-14.el9_3.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: bind-dyndb-ldap-0:11.9-8.el9_3.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: bind-32:9.16.23-18.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: dnsmasq-0:2.85-3.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: bind-32:9.16.23-1.el9_0.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: bind-dyndb-ldap-0:11.9-7.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: unbound-0:1.13.1-13.el9_0.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: unbound-0:1.16.2-3.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: dnsmasq-0:2.85-6.el9_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: bind-32:9.16.23-11.el9_2.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: bind-dyndb-ldap-0:11.9-8.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: bind-dyndb-ldap-0:11.9-9.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONFixed in: bind-32:9.8.2-0.68.rc1.el6_10.14
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONFixed in: bind-dyndb-ldap-0:2.3-8.el6_10.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: bind-32:9.11.4-26.P2.el7_9.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: bind-dyndb-ldap-0:11.1-7.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: dhcp-12:4.2.5-83.el7_9.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: unbound-0:1.6.6-5.el7_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: unbound-0:1.16.2-5.el8_9.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dnsmasq-0:2.79-31.el8_9.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: bind9.16-32:9.16.23-0.16.el8_9.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: bind-32:9.11.36-11.el8_9.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: bind-32:9.11.36-14.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: unbound-0:1.7.3-12.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: bind-32:9.11.13-6.el8_2.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: dhcp-12:4.3.6-40.el8_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: dnsmasq-0:2.79-11.el8_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: unbound-0:1.7.3-12.el8_2.1
View patch
alistgovendor investigatingvia llm_extracted
View patch
consensysvendor investigatingvia llm_extracted
View patch

Vendor Advisories (7)

denollm-deno-b67a3af2ce0be075CRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
kerasllm-keras-7d8c31fee70361dcCRITICAL

HP ThinPro 8.0 SP 9 Security Updates

Jun 17, 2024
microsoft2024-Feb/CVE-2023-50387Important

MITRE: CVE-2023-50387 DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers

Feb 13, 2024
redhatCVE-2023-50387Important

bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator

Feb 13, 2024
nessusllm-nessus-8db28c9b01845a1a
consensysllm-consensys-e5b7940526f94c5a
alistgollm-alistgo-ff2daa4e76c50e49

KeyTrap - Extreme CPU consumption in DNSSEC validator

References

lists.debian.org / debian-lts-announce/2024/09/msg00001.html
lists.debian.org / debian-lts-announce/2024/11/msg00035.html
lists.fedoraproject.org / archives/list/[email protected]/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI
lists.fedoraproject.org / archives/list/[email protected]/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ
lists.fedoraproject.org / archives/list/[email protected]/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ
lists.fedoraproject.org / archives/list/[email protected]/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R
access.redhat.com / security/cve/CVE-2023-50387
Third Party Advisory
bugzilla.suse.com / show_bug.cgi
Issue Tracking
docs.powerdns.com / recursor/security-advisories/powerdns-advisory-2024-01.html
Third Party Advisory
gitlab.nic.cz / knot/knot-resolver/-/releases/v5.7.1
Patch
kb.isc.org / docs/cve-2023-50387
Third Party AdvisoryVDB Entry
lists.debian.org / debian-lts-announce/2024/02/msg00006.html
lists.debian.org / debian-lts-announce/2024/05/msg00011.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI
Mailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ
Mailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP
Mailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R
lists.thekelleys.org.uk / pipermail/dnsmasq-discuss/2024q1/017430.html
Mailing ListThird Party Advisory
msrc.microsoft.com / update-guide/vulnerability/CVE-2023-50387
PatchVendor Advisory
news.ycombinator.com / item
Third Party Advisory
news.ycombinator.com / item
Issue Tracking
nlnetlabs.nl / news/2024/Feb/13/unbound-1.19.1-released
Vendor Advisory
security.netapp.com / advisory/ntap-20240307-0007
athene-center.de / aktuelles/key-trap
Third Party Advisory
athene-center.de / fileadmin/content/PDF/Technical_Report_KeyTrap.pdf
Technical DescriptionThird Party Advisory
isc.org / blogs/2024-bind-security-release
Third Party Advisory
securityweek.com / keytrap-dns-attack-could-disable-large-parts-of-internet-researchers
Press/Media CoverageThird Party Advisory
theregister.com / 2024/02/13/dnssec_vulnerability_internet
PatchThird Party Advisory
openwall.com / lists/oss-security/2024/02/16/2
Mailing List
openwall.com / lists/oss-security/2024/02/16/3
Mailing List