6.2
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.
Basic Information
ID
CVE-2026-35406
Source
GitHub_M
Published
Apr 7, 2026 at 21:32
Modified
Apr 8, 2026 at 16:14
Affected Product
Vendor
containers
Product
aardvark-dns
Version
>= 1.16.0, < 1.17.1
Affected Versions
containers aardvark-dns >= 1.16.0, < 1.17.1