hickory-resolver is vulnerable to Denial of Service (DoS)
75
High Risk
For referrals that lack in-bailiwick glue, the recursor iterates every listed name server target and issues A and AAAA lookups for each, recursing with the same depth counters and no per-query width or work budget. Crafted delegations can fan this out into a large number of upstream queries. This enables amplification against remote servers and local resource exhaustion. The fix adds a per-query work budget.
You are affected if you are using a version that falls within the vulnerable range and you use the recursive resolver
hickory-resolver is vulnerable to Denial of Service (DoS) in versions 0.26.0 - 0.26.1.
Upgrade the hickory-resolver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.