Users using the ValidatingResolver
for DNSSEC validation can run into CPU exhaustion with specially crafted DNSSEC-signed zones.
Users should upgrade to dnsjava v3.6.0
Although not recommended, only using a non-validating resolver, will remove the vulnerability.
https://www.athene-center.de/en/keytrap
{ "nvd_published_at": null, "cwe_ids": [ "CWE-770" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-07-22T17:30:19Z" }