mediumVulnerability
GHSA-6f2x-v7q7-m7m5
When the Hickory DNS resolver follows CNAME records, it sends queries that are not necessary to answer the original recursive query. If there are any CNAME records in the authority section or additional section of the response, queries will be sent for those names. If there are any CNAME records that are not part of a CNAME chain starting from the original recursive query name, queries will be sent for those names. This increases query amplification beyond what is necessary to answer the recursive query.
Properties
- ghsa_id
- GHSA-6f2x-v7q7-m7m5
- severity
- medium
- summary
- hickory-resolver follows irrelevant CNAME records
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-6f2x-v7q7-m7m5
- signal_observed_at
- 2026-10-06T02:58:31+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-06T03:05:59+00:00
- ghsa_published
- 2026-10-05T22:55:18Z
- source_url
- https://github.com/advisories/GHSA-6f2x-v7q7-m7m5
- ghsa_updated
- 2026-10-05T22:55:20Z
Related Entities (4)
HAS_WEAKNESS (1)
→[Weakness]Uncontrolled Resource Consumption
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]rust/hickory-resolver
AFFECTS (1)
→[Software]rust/hickory-resolver
Explore deeper with Ninja Signal's threat intelligence graph