c-ares.c-ares is vulnerable to Use After Free
69
Medium Risk
Use after free() in read_answer() when process_answer() may terminate a query such as after maximum attempts. This was causing the connection to be closed, but still possibly additional answers to be processed. This is a missed case from CVE-2025-31498.
You are affected if you are using a version that falls within the vulnerable range.
c-ares.c-ares is vulnerable to Use After Free in versions 1.32.3 - 1.34.5.
Upgrade the c-ares.c-ares library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant