{"id":"CVE-2025-24294","aliases":["GHSA-xh69-987w-hrp8"],"url":"https://o3.security/vulnerability/CVE-2025-24294","summary":"resolv vulnerable to DoS via insufficient DNS domain name length validation","details":"The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet.\r\n\r\nAn attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name.\r\n\r\nThis resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition.","published":"2025-07-12T04:15:46Z","modified":"2026-04-10T05:23:01.358562Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"resolv","fixedVersion":"0.2.3"},{"ecosystem":"RubyGems","name":"resolv","fixedVersion":"0.6.2"},{"ecosystem":"RubyGems","name":"resolv","fixedVersion":"0.3.1"}],"fix":null,"references":[{"type":"WEB","url":"https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T05:23:01.358562Z"}}