OVERVIEW CVE-2026-35406 affects Aardvark-dns, an authoritative DNS server for container A/AAAA records, in versions 1.16.0 through 1.17.0. A vulnerability exists where a truncated TCP DNS query followed by a connection reset causes the service to enter an unrecoverable infinite error loop, consuming 100% CPU resources. The vulnerability has been patched in version 1.17.1. SEVERITY This vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity, making it relatively straightforward to execute remotely. The primary impact is availability denial through resource exhaustion rather than confidentiality or integrity compromise. An attacker can trigger a complete denial of service condition by crafting specific malformed DNS queries. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as this CVE does not appear on the known exploited vulnerabilities (KEV) catalog and remains inactive on threat tracking lists. The EPSS score of 0.00013 indicates minimal probability of exploitation, placing it below the 0.02% baseline for all CVEs. No public exploit code is readily available, though the straightforward nature of the attack vector suggests exploitation would be trivial once discovered. Organizations should prioritize updating to version 1.17.1, particularly if running Aardvark-dns in production container environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.16.0, < 1.17.1CPE matchmatch criteria | cpe:2.3:a:containers:aardvark-dns:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.