GHSA-6f2x-v7q7-m7m5

Suggest an improvement
Source
https://github.com/advisories/GHSA-6f2x-v7q7-m7m5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6f2x-v7q7-m7m5/GHSA-6f2x-v7q7-m7m5.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6f2x-v7q7-m7m5
Published
2026-10-05T22:55:18Z
Modified
2026-10-05T23:15:09Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
hickory-resolver follows irrelevant CNAME records
Details

When the Hickory DNS resolver follows CNAME records, it sends queries that are not necessary to answer the original recursive query. If there are any CNAME records in the authority section or additional section of the response, queries will be sent for those names. If there are any CNAME records that are not part of a CNAME chain starting from the original recursive query name, queries will be sent for those names. This increases query amplification beyond what is necessary to answer the recursive query.

Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T22:55:18Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / hickory-resolver

Package

Name
hickory-resolver
View open source insights on deps.dev
Purl
pkg:cargo/hickory-resolver

Affected ranges

Type
SEMVER
Events
Introduced
0.25.0
Fixed
0.26.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6f2x-v7q7-m7m5/GHSA-6f2x-v7q7-m7m5.json"