Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
https://lists.debian.org/debian-lts-announce/2022/10/msg00008.html
https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1343#note_262558