hickory-resolver is vulnerable to Denial of Service (DoS)
75
High Risk
When the name server pool receives a response with the TC (truncated) bit set, it requeues the request to retry without inspecting the transport or counting iterations. An upstream that sets TC on every transport keeps the resolver retrying on a single connection until the wall-clock deadline. This ties up the resolver and denies timely resolution. The fix inspects the transport and bounds retries.
You are affected if you are using a version that falls within the vulnerable range.
hickory-resolver is vulnerable to Denial of Service (DoS) in versions 0.26.0 - 0.26.1.
Upgrade the hickory-resolver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.