---
id: GHSA-6w6g-hm98-mhgm
title: >-
  hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send`
  (resource-exhaustion DoS)
summary: >-
  hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send`
  (resource-exhaustion DoS)
severity: high
cwe:
  - CWE-400
  - CWE-406
  - CWE-835
vendor: hickory-resolver
product: hickory-resolver
ecosystem: rust
affected:
  - 'hickory-resolver >= 0.26.0-beta.1, < 0.26.2'
patched:
  - hickory-resolver 0.26.2
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T22:55:12Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-6w6g-hm98-mhgm'
references:
  - url: >-
      https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-6w6g-hm98-mhgm
  - url: 'https://github.com/hickory-dns/hickory-dns/pull/3871'
  - url: >-
      https://github.com/hickory-dns/hickory-dns/commit/0848d2e9e4183499343318a690d6dd5e48bc21c1
  - url: >-
      https://github.com/hickory-dns/hickory-dns/commit/5d37e2e04a36a87013a213b58b820345ef76a263
  - url: 'https://github.com/hickory-dns/hickory-dns/releases/tag/v0.26.2'
  - url: 'https://github.com/advisories/GHSA-6w6g-hm98-mhgm'
tags:
  - ghsa
  - rust
ingestedAt: '2026-10-05T23:36:21.172Z'
---

## Overview

When the `hickory-resolver` name server pool implementation receives an upstream response with the TC (truncated) header bit set, it re-queues the request to the same nameserver to retry with UDP transport disabled. However, the retry arm never inspects the transport that just answered and carries no iteration counter. An authoritative server that sets `TC=1` on **every** available transport  keeps the resolver spinning on one persistent TCP connection until the 5s per-request wall-clock deadline expires.

### Reporter

Qifan Zhang, Palo Alto Networks

## Affected packages

- `hickory-resolver >= 0.26.0-beta.1, < 0.26.2`

## Remediation

Upgrade to a patched release:

- `hickory-resolver 0.26.2`
