Intel

AIKIDO-2026-114877

hickory-resolver is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-6w6g-hm98-mhgm Published 3 days ago

75

High Risk

This Affects:

RUSThickory-resolver
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

When the name server pool receives a response with the TC (truncated) bit set, it requeues the request to retry without inspecting the transport or counting iterations. An upstream that sets TC on every transport keeps the resolver retrying on a single connection until the wall-clock deadline. This ties up the resolver and denies timely resolution. The fix inspects the transport and bounds retries.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

hickory-resolver is vulnerable to Denial of Service (DoS) in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-resolver library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform