Intel

AIKIDO-2026-585858

hickory-net is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-v44v-c8m4-gc43 Published 3 days ago

59

Medium Risk

This Affects:

RUSThickory-net
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

A client UDP connection that receives an unparseable datagram while awaiting a response stops listening and returns an error instead of ignoring the bad datagram. Because only the source port must be guessed, not the transaction ID, a spoofed malformed datagram can terminate a pending query. This is the denial-of-service variant of the TuDoor attack. The fix ignores malformed datagrams and keeps listening.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

hickory-net is vulnerable to Denial of Service (DoS) in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-net library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform