Vulnerability GHSA-6f2x-v7q7-m7m5
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
8 hours ago
October 05, 2026 at 10:55 PM UTC
hickory-resolver follows irrelevant CNAME records
0.25.0 - 0.25.2 and 0.26.0 - 0.26.1
0.25.0 - 0.25.2 and 0.26.0 - 0.26.1
Summary
hickory-resolver follows irrelevant CNAME records
Details
When the Hickory DNS resolver follows CNAME records, it sends queries that are not necessary to answer the original recursive query. If there are any CNAME records in the authority section or additional section of the response, queries will be sent for those names. If there are any CNAME records that are not part of a CNAME chain starting from the original recursive query name, queries will be sent for those names. This increases query amplification beyond what is necessary to answer the recursive query.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
8 hours ago
hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)
0.26.0-beta.1 - 0.26.1 GHSA-6w6g-hm98-mhgm
0.26.0-beta.1 - 0.26.1 GHSA-6w6g-hm98-mhgm
High Risk
8 hours ago
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
0.1.0 - 0.24.4 and 0.25.0 - 0.25.2 and 0.26.0 - 0.26.1 GHSA-5j98-2g5x-46v6
0.1.0 - 0.24.4 and 0.25.0 - 0.25.2 and 0.26.0 - 0.26.1 GHSA-5j98-2g5x-46v6
Impacted packages
Timeline
Published
8 hours ago
October 05, 2026 at 10:55 PM UTC
Fixed (0.26.2)
1 month ago
September 03, 2026 at 07:35 PM UTC
Last Modified
8 hours ago
October 05, 2026 at 11:15 PM UTC