Resource exhaustion in resolv - CVE-2026-80212
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the resolv DNS resolution logic when processing malicious DNS responses from an attacker-controlled name server. A remote attacker can return crafted DNS responses that are retained permanently to cause a denial of service.
Only applications that resolve hostnames an attacker can influence through this gem are affected.