GHSA-pgf6-87r4-94vmMediumCVSS 5.9

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response...

Published
August 4, 2026
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.

Repeated triggering of this condition can lead to denial of service.

This vulnerability affects Node.js 26.x, 24.x, and 22.x.

🔗 References (3)