hickory-resolver follows irrelevant CNAME records
Moderate severity
GitHub Reviewed
Published
Sep 3, 2026
in
hickory-dns/hickory-dns
•
Updated Oct 5, 2026
Description
Published to the GitHub Advisory Database
Oct 5, 2026
Reviewed
Oct 5, 2026
Last updated
Oct 5, 2026
When the Hickory DNS resolver follows CNAME records, it sends queries that are not necessary to answer the original recursive query. If there are any CNAME records in the authority section or additional section of the response, queries will be sent for those names. If there are any CNAME records that are not part of a CNAME chain starting from the original recursive query name, queries will be sent for those names. This increases query amplification beyond what is necessary to answer the recursive query.
References