hickory-resolver is vulnerable to Denial of Service (DoS)
30
Low Risk
When following CNAME records, the resolver issues queries for CNAME records found in the authority and additional sections and for CNAMEs that are not part of the chain starting at the original query name. These extra queries are unnecessary to answer the original request and increase outbound query amplification. Untrusted responses can drive this amplification against upstream servers. The fix only follows CNAMEs that belong to the relevant chain.
You are affected if you are using a version that falls within the vulnerable range and you use the recursive resolver
hickory-resolver is vulnerable to Denial of Service (DoS) in versions 0.25.0 - 0.26.1.
Upgrade the hickory-resolver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.