6.5
CVSS V3
DNSJava vulnerable to KeyTrap - Denial-of-Service Algorithmic Complexity Attacks
Users using the ValidatingResolver
for DNSSEC validation can run into CPU exhaustion with specially crafted DNSSEC-signed zones.
Users should upgrade to dnsjava v3.6.0
Although not recommended, only using a non-validating resolver, will remove the vulnerability.