mediumVulnerability

GHSA-6f2x-v7q7-m7m5

When the Hickory DNS resolver follows CNAME records, it sends queries that are not necessary to answer the original recursive query. If there are any CNAME records in the authority section or additional section of the response, queries will be sent for those names. If there are any CNAME records that are not part of a CNAME chain starting from the original recursive query name, queries will be sent for those names. This increases query amplification beyond what is necessary to answer the recursive query.

Properties

ghsa_id
GHSA-6f2x-v7q7-m7m5
severity
medium
summary
hickory-resolver follows irrelevant CNAME records
last_source
GitHub Advisory Database
cve_id
GHSA-6f2x-v7q7-m7m5
signal_observed_at
2026-10-06T02:58:31+00:00
is_ghsa_only
true
retrieved_at
2026-10-06T03:05:59+00:00
ghsa_published
2026-10-05T22:55:18Z
source_url
https://github.com/advisories/GHSA-6f2x-v7q7-m7m5
ghsa_updated
2026-10-05T22:55:20Z

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]rust/hickory-resolver

AFFECTS (1)

→[Software]rust/hickory-resolver

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-6f2x-v7q7-m7m5 — Ninja Signal Threat Intelligence | Ninja Signal