{"id":"CVE-2022-22846","aliases":["GHSA-r478-c2pc-m7gx","PYSEC-2022-4"],"url":"https://o3.security/vulnerability/CVE-2022-22846","summary":"dnslib has DNS reply verification issue","details":"The dnslib package through 0.9.16 for Python does not verify that the ID value in a DNS reply matches an ID value in a query.","published":"2022-01-09T00:49:30Z","modified":"2026-08-12T03:51:12.668319979Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AC:L/AV:N/A:N/C:N/I:H/PR:N/S:U/UI:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"dnslib","fixedVersion":"0.9.17"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/22xxx/CVE-2022-22846.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-22846"},{"type":"REPORT","url":"https://github.com/paulc/dnslib/issues/30"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.668319979Z"}}