hickory-resolver is vulnerable to Denial of Service (DoS)
75
High Risk
When two zones reference each other through cyclic sibling name servers that lack the required glue records, the recursor keeps chasing the referrals in a loop until the per-request query budget is exhausted. Each pass issues additional upstream queries, producing exponential query amplification. Crafted zones can drive large volumes of traffic to upstream servers. The fix detects cyclic referrals and bounds the work.
You are affected if you are using a version that falls within the vulnerable range and you use the recursive resolver
hickory-resolver is vulnerable to Denial of Service (DoS) in versions 0.26.0 - 0.26.1.
Upgrade the hickory-resolver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.