VYPR

Resolv

by Ruby Lang

gem: resolv

Source repositories

CVEs (4)

  • CVE-2026-80212HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource::Generic.create, and Resolv::DNS::SvcParam::Generic.create generate a new class for each unknown DNS resource record (type, class) pair, or each unknown…

  • CVE-2025-24294HigJul 12, 2025
    risk 0.42cvss 7.5epss 0.01

    The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the…

  • CVE-2026-80213MedAug 27, 2026
    risk 0.19cvss 4.0epss 0.00

    An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A label longer than 255 octets had its length stored modulo 256 but the label data was written unchanged, and…

  • CVE-2008-3905Sep 4, 2008
    risk 0.00cvss —epss 0.02

    resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different…