Input validation error in resolv - CVE-2026-80213
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass hostname validation restrictions.
The vulnerability exists due to improper input validation in the resolv hostname resolution logic when resolving a hostname after it has been checked against an allow list or SSRF filter. A remote attacker can supply a crafted hostname so that the validated string and the name sent to the network differ to bypass hostname validation restrictions.
This requires a hostname that exceeds DNS length limits.