CVE-2026-35406
Received Received - Intake
Infinite Loop CPU Exhaustion in Aardvark-dns TCP Queries

Publication date: 2026-04-07

Last updated on: 2026-04-16

Assigner: GitHub, Inc.

Description
Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-07
Last Modified
2026-04-16
Generated
2026-05-06
AI Q&A
2026-04-08
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
containers aardvark-dns From 1.16.0 (inc) to 1.17.1 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability affects aardvark-dns, an authoritative DNS server for A/AAAA container records. Specifically, versions from 1.16.0 to 1.17.0 are impacted. When a truncated TCP DNS query is followed by a connection reset, the server enters an unrecoverable infinite error loop that consumes 100% CPU.

This issue was fixed in version 1.17.1 of aardvark-dns.


How can this vulnerability impact me? :

The vulnerability can cause the aardvark-dns server to enter an infinite error loop, resulting in 100% CPU usage. This can lead to denial of service as the server becomes unresponsive or unable to process legitimate DNS queries.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, upgrade aardvark-dns to version 1.17.1 or later, where the issue is fixed.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart