c-ares
3 known vulnerabilities in c-ares, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-69186 CVSS 5.3 medium c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT…
- CVE-2026-69184 CVSS 7.5 high c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not…
- CVE-2026-33630 CVSS 7.5 high c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion…