C Ares is a DNS resolver library embedded across a large range of systems and applications despite its narrow product scope, giving its vulnerabilities impact disproportionate to its volume—a single flaw can propagate to every downstream consumer of the library. The recurring exposure reflects the parsing and protocol complexity inherent to DNS resolution, and defenders should inventory affected dependencies rather than tracking the library alone, since remediation typically depends on downstream vendors rebuilding. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by C Ares over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8277HIGH A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 b | Nov 19, 2020 | 7.5 | 54 | NO | NO |
CVE-2016-5180CRITICAL Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly exec | Oct 3, 2016 | 9.8 | 36 | NO | NO |
CVE-2017-1000381HIGH The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS | Jul 7, 2017 | 7.5 | 27 | NO | NO |
CVE-2023-32067HIGH c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length | May 25, 2023 | 7.5 | 23 | NO | NO |
CVE-2025-62408MEDIUM c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause | Dec 8, 2025 | 5.9 | 22 | NO | NO |
CVE-2021-3672MEDIUM A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might pot | Nov 23, 2021 | 5.6 | 22 | NO | NO |
CVE-2023-31147MEDIUM c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a | May 25, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-4904HIGH A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. Thi | Mar 6, 2023 | 8.6 | 21 | NO | NO |
CVE-2023-31130MEDIUM c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an | May 25, 2023 | 6.4 | 20 | NO | NO |
CVE-2020-22217MEDIUM Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c. | Aug 22, 2023 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by C Ares.
Media articles that mention a CVE ID that affects a product developed by C Ares — matched by CVE ID, not by vendor name.