Intel

AIKIDO-2026-534453

c-ares.c-ares is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-69184 Published 5 days ago

75

High Risk

This Affects:

C++c-ares.c-ares
1.22.0 - 1.34.6
Fixed in 1.34.7
Are you affected? Scan for Free

TL;DR

Name decompression in c-ares follows DNS compression pointers with no cap on the number of hops or the assembled name length. A response that builds a long pointer chain and points many records at that chain repeats the walk for every record. Because resolution runs on one event loop thread, one response can stall every lookup in the process. The fix caps compression hops at 128 and enforces the 255 octet limit while the name is assembled.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

c-ares.c-ares is vulnerable to Denial of Service (DoS) in versions 1.22.0 - 1.34.6.

How to fix this

Upgrade the c-ares.c-ares and/or the c-ares library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform