CVE-2025-62408: C-Ares
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts when using read_answer() and process_answer(), which can cause a Denial of Service. This issue is fixed in version 1.34.6.
Affected products
- C-Ares C-Ares: from 1.32.3, before 1.34.6 (fixed in 1.34.6)
Published 2025-12-08. Last modified 2026-06-17.