GHSA-6w6g-hm98-mhgmHigh▾ Twilighthickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When the hickory-resolver name server pool implementation receives an upstream response with the TC (truncated) header bit set, it re-queues the request to the same nameserver to retry with UDP transport disabled. However, the retry arm never inspects the transport that just answered and carries no iteration counter. An authoritative server that sets TC=1 on every available transport keeps the resolver spinning on one persistent TCP connection until the 5s per-request wall-clock deadline expires.
Qifan Zhang, Palo Alto Networks
hickory-resolver >= 0.26.0-beta.1, < 0.26.2Upgrade to a patched release:
hickory-resolver 0.26.2Connected by shared product, vendor, weakness, or advisory.
GHSA-6f2x-v7q7-m7m5Mediumhickory-resolver follows irrelevant CNAME records
GHSA-5j98-2g5x-46v6High· 7.5hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
CVE-2026-93657High· 7.5hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results
CVE-2026-102997High· 7.5pypdf is a free and open-source pure-python PDF library
CVE-2026-101895HighAngular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
CVE-2025-48392High· 7.5A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version 2.0.5, which fixes the issue.