PatchSiren cyber security CVE debrief
CVE-2026-35406 containers CVE debrief
Aardvark-dns, an authoritative DNS server for A/AAAA container records, is vulnerable to an infinite error loop at 100% CPU caused by a truncated TCP DNS query followed by a connection reset. This issue affects versions from 1.16.0 to 1.17.0 and is fixed in version 1.17.1. The vulnerability has a CVSS score of 6.2, indicating medium severity. Users of Aardvark-DNS should update to version 1.17.1 to prevent potential denial-of-service attacks. The vulnerability allows an attacker to cause the server to enter an unrecoverable infinite error loop at 100% CPU. The issue was introduced in version 1.16.0 and was fixed in version 1.17.1.
- Vendor
- containers
- Product
- aardvark-dns
- CVSS
- MEDIUM 6.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Users of Aardvark-DNS versions 1.16.0 through 1.17.0 should update to version 1.17.1 to prevent potential denial-of-service attacks. Security teams and operators managing Aardvark-DNS deployments should review the vulnerability details and plan for updates or mitigations. Platform administrators and vulnerability management teams should also be aware of the potential impact and verify their environments.
Technical summary
The vulnerability in Aardvark-DNS allows an attacker to cause the server to enter an unrecoverable infinite error loop at 100% CPU by sending a truncated TCP DNS query followed by a connection reset. This issue was introduced in version 1.16.0 and was fixed in version 1.17.1. The CVSS score for this vulnerability is 6.2, indicating a medium severity. The vulnerability affects Aardvark-DNS versions from 1.16.0 to 1.17.0. Users should verify their deployments and update to version 1.17.1.
Defensive priority
Medium priority due to potential for denial-of-service attacks. Security teams should prioritize updates and monitoring for Aardvark-DNS deployments.
Recommended defensive actions
- Update Aardvark-DNS to version 1.17.1 or later
- Monitor for unusual traffic patterns that could indicate exploitation attempts
- Implement network segmentation to limit the impact of a potential attack
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-07T22:16:23.277Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The vulnerability affects Aardvark-DNS versions from 1.16.0 to 1.17.0. Users should verify their deployments and update to version 1.17.1. The CVE details are sourced from official records, but the impact and affected scope may require further verification.
Official resources
-
CVE-2026-35406 CVE record
CVE.org
-
CVE-2026-35406 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Release Notes
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T22:16:23.277Z and has not been modified since then. The NVD entry is currently Analyzed.