CVE-2026-69184
Last modified
CVE-2026-69184 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing a long descending pointer chain and many resource records whose NAME or RDATA fields refer to the chain, causing repeated decompression work that grows quadratically with message size. A single crafted response can stall the single-threaded c-ares event loop and deny DNS resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| c-ares | c-ares | < 1.34.7 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-69184?
How severe is CVE-2026-69184?
How do I fix CVE-2026-69184?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69153PostCSS takes a CSS file and provides an API to analyze and …5.3
- CVE-2026-69159Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-6916The Jeg Kit for Elementor – Powerful Addons for Elementor, W…6.4
- CVE-2026-69160OpenList a file list program that supports multiple storage.…6.5
- CVE-2026-6918In Eclipse Open9J versions 0.21 to 0.58, a pre-authenticatio…7.5
- CVE-2026-69183Monkeytype is a minimalistic and customizable typing test. I…7.5
- CVE-2026-69185Socket.IO enables bidirectional and low-latency communicatio…7.5
- CVE-2026-69186c-ares is an asynchronous resolver library. Prior to 1.34.7,…5.3
- CVE-2026-69189Hoppscotch is an open source API development ecosystem. Prio…7.6
- CVE-2026-6919Use after free in DevTools in Google Chrome prior to 147.0.7…9.6
- CVE-2026-69190Graylog is a free and open log management platform. From 6.3…6.3
- CVE-2026-69192ip-address is a library for parsing and manipulating IPv4 an…7.7
Are you affected by CVE-2026-69184?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
