Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35406

25
FAUCET Score

OVERVIEW CVE-2026-35406 affects Aardvark-dns, an authoritative DNS server for container A/AAAA records, in versions 1.16.0 through 1.17.0. A vulnerability exists where a truncated TCP DNS query followed by a connection reset causes the service to enter an unrecoverable infinite error loop, consuming 100% CPU resources. The vulnerability has been patched in version 1.17.1. SEVERITY This vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity, making it relatively straightforward to execute remotely. The primary impact is availability denial through resource exhaustion rather than confidentiality or integrity compromise. An attacker can trigger a complete denial of service condition by crafting specific malformed DNS queries. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as this CVE does not appear on the known exploited vulnerabilities (KEV) catalog and remains inactive on threat tracking lists. The EPSS score of 0.00013 indicates minimal probability of exploitation, placing it below the 0.02% baseline for all CVEs. No public exploit code is readily available, though the straightforward nature of the attack vector suggests exploitation would be trivial once discovered. Organizations should prioritize updating to version 1.17.1, particularly if running Aardvark-dns in production container environments.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.16.0, < 1.17.1CPE matchmatch criteria
cpe:2.3:a:containers:aardvark-dns:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.2MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.5
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.38%
Probability of exploitation in next 30 days
EPSS Percentile
30.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0038 is in the 11th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1
Patch
github.com / containers/aardvark-dns/releases/tag/v1.17.1
Release Notes
github.com / containers/aardvark-dns/security/advisories/GHSA-hfpq-x728-986j
PatchVendor Advisory