resolv
Thread-aware DNS resolver library in Ruby.
Activity
- Latest release
- 7mo ago
- Total releases
- 15
- Cadence
- ~3 months
- Last 12 months
- 3
Details
- License
- unknown OR BSD-2-Clause
- First release
- Sep 18, 2020
| Version | Released | |
|---|---|---|
0.7.1
patch
| ||
0.7.0
minor
| ||
0.6.3
patch
| ||
0.2.3
patch
| ||
0.3.1
patch
| ||
0.6.2
patch
| ||
0.6.1
patch
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.2
patch
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.1
patch
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
CVE-2025-24294
GHSA-xh69-987w-hrp8
Jul 15, 2025
resolv vulnerable to DoS via insufficient DNS domain name length validation
Medium
Network
Low
None
None
A denial of service vulnerability has been discovered in the resolv gem bundled with Ruby. DetailsThe vulnerability is caused by an insufficient check on the length of a decompressed domain name within a DNS packet. An attacker can craft a malicious DNS packet containing a highly compressed domain name. When the resolv library parses such a packet, the name decompression process consumes a large amount of CPU resources, as the library does not limit the resulting length of the name. This resource consumption can cause the application thread to become unresponsive, resulting in a Denial of Service condition. Affected VersionThe vulnerability affects the resolv gem bundled with the following Ruby series:
CreditsThanks to Manu for discovering this issue. HistoryOriginally published at 2025-07-08 07:00:00 (UTC) Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.4.0
0.5.0
0.6.0
0.6.1
0.3.0
Fixed in
0.2.3
0.3.1
0.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev |