Vulnerability GHSA-6w6g-hm98-mhgm

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 hours ago
October 05, 2026 at 10:55 PM UTC
hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)
0.26.0-beta.1 - 0.26.1
0.26.0-beta.1 - 0.26.1

Summary

hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)

Details

When the hickory-resolver name server pool implementation receives an upstream response with the TC (truncated) header bit set, it re-queues the request to the same nameserver to retry with UDP transport disabled. However, the retry arm never inspects the transport that just answered and carries no iteration counter. An authoritative server that sets TC=1 on every available transport keeps the resolver spinning on one persistent TCP connection until the 5s per-request wall-clock deadline expires.

Reporter

Qifan Zhang, Palo Alto Networks

Impacted packages

Timeline

Published
8 hours ago
October 05, 2026 at 10:55 PM UTC
Fixed (0.26.2)
1 month ago
September 03, 2026 at 07:35 PM UTC
Last Modified
8 hours ago
October 05, 2026 at 11:15 PM UTC