CVE-2020-8277
published 2020-11-19CVE-2020-8277: A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, <…
PriorityP355high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
54.16%
98.9th percentile
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| c-ares | c-ares | >= 0 < 1.17.1-1 | 1.17.1-1 |
| c-ares | c-ares | >= 0 < 1.17.1-1 | 1.17.1-1 |
| c-ares | c-ares | >= 0 < 1.17.1-1 | 1.17.1-1 |
| c-ares | c-ares | >= 0 < 1.17.1-1 | 1.17.1-1 |
| c-ares_project | c-ares | < 1.16.0 | 1.16.0 |
| debian | c-ares | < c-ares 1.17.1-1 (bookworm) | c-ares 1.17.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_python-gevent_21.1.2-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_c-ares_1.17.1-1_on_cbl_mariner_1.0 | — | — |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.19.1 | 12.19.1 |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.15.1 | 14.15.1 |
| nodejs | node | >= 15.0 < 15.2.1 | 15.2.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | node.js | >= 12.16.3 < 12.19.1 | 12.19.1 |
| nodejs | node.js | >= 14.13.0 < 14.15.1 | 14.15.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: attacker causes the Node.js application to resolve a DNS record with a larger number of responses, exploiting insufficient naddrttls validation in c-ares ares_parse_{a,aaaa}_reply() ↗
- →Vulnerable component is c-ares library functions ares_parse_a_reply() and ares_parse_aaaa_reply() — monitor for abnormally large DNS response answer counts processed by these functions ↗
- →Attack vector is network/remote over HTTP; flag Node.js applications that allow user-controlled DNS resolution targets as high-risk attack surface ↗
- ·Fixed versions for Node.js are 15.2.1, 14.15.1, and 12.19.1 — any Node.js deployment below these versions remains vulnerable ↗
- ·Red Hat Enterprise Linux 5/6/7/8 standalone c-ares packages are NOT affected; only Node.js bundled c-ares is the concern ↗
- ·Debian fixed version for c-ares is 1.17.1-1 across bookworm, bullseye, forky, sid, and trixie ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Node.js) — CVE-2020-8277
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2020-8277 [HIGH] Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Node.js) — CVE-2020-8277
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Node.js) vulnerability
CVE: CVE-2020-8277
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) — CVE-2020-8277
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2020-8277 [HIGH] Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) — CVE-2020-8277
Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) vulnerability
CVE: CVE-2020-8277
CVSS: 7.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle GraalVM Risk Matrix: Node (Node.js) — CVE-2020-8277
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2020-8277 [HIGH] Oracle Oracle GraalVM Risk Matrix: Node (Node.js) — CVE-2020-8277
Oracle Oracle GraalVM Risk Matrix: Node (Node.js) vulnerability
CVE: CVE-2020-8277
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Ubuntu
c-ares vulnerability
vendor_ubuntu·2020-11-19
CVE-2020-8277 c-ares vulnerability
Title: c-ares vulnerability
Summary: c-ares could be made to denial of service if it received a specially crafted
DNS request.
It was discovered that c-ares incorrectly handled certain DNS requests.
An attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS
vendor_redhat·2020-11-12·CVSS 7.5
CVE-2020-8277 [HIGH] CWE-119 c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS
c-ares: ares_parse_{a,aaaa}_reply() insufficient naddrttls validation DoS
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
Package: c-ares (Red Hat Enterprise Linux 5) - Not affected
Package: c-ares (Red Hat Enterprise Linux 6) - Not affected
Package: c-ares (Red Hat Enterprise Linux 7) - Not affected
Package: c-ares (Red Hat Enterprise Linux 8) - Not affected
Package: nodejs:10/nodejs (Red Hat Enterprise Linux 8) - Not affected
Package: rh-nodejs10-nodejs (Red Hat Software Collections) - Not affected
Microsoft
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1 < 14.15.1 and < 12.19.1 by getting the applicat
vendor_msrc·2020-11-10·CVSS 7.5
CVE-2020-8277 [HIGH] CWE-400 A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1 < 14.15.1 and < 12.19.1 by getting the applicat
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
Debian
CVE-2020-8277: c-ares - A Node.js application that allows an attacker to trigger a DNS request for a hos...
vendor_debian·2020·CVSS 7.5
CVE-2020-8277 [HIGH] CVE-2020-8277: c-ares - A Node.js application that allows an attacker to trigger a DNS request for a hos...
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
Scope: local
bookworm: resolved (fixed in 1.17.1-1)
bullseye: resolved (fixed in 1.17.1-1)
forky: resolved (fixed in 1.17.1-1)
sid: resolved (fixed in 1.17.1-1)
trixie: resolved (fixed in 1.17.1-1)
GHSA
Uncontrolled Resource Consumption in node
ghsa_unreviewed·2021-04-14
CVE-2020-8277 [HIGH] CWE-400 Uncontrolled Resource Consumption in node
Uncontrolled Resource Consumption in node
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
OSV
CVE-2020-8277: A Node
osv·2020-11-19·CVSS 7.5
CVE-2020-8277 [HIGH] CVE-2020-8277: A Node
A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://hackerone.com/reports/1033107https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A7WH7W46OZSEUHWBHD7TCH3LRFY52V6Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEJBY3RJB3XWUOJFGZM5E3EMQ7MFM3UT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EEIV4CH6KNVZK63Y6EKVN2XDW7IHSJBJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VXLJY4764LYVJPC7NCDLE2UMQ3QC5OI2/https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/https://security.gentoo.org/glsa/202012-11https://security.gentoo.org/glsa/202101-07https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://hackerone.com/reports/1033107https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A7WH7W46OZSEUHWBHD7TCH3LRFY52V6Z/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEJBY3RJB3XWUOJFGZM5E3EMQ7MFM3UT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EEIV4CH6KNVZK63Y6EKVN2XDW7IHSJBJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VXLJY4764LYVJPC7NCDLE2UMQ3QC5OI2/https://nodejs.org/en/blog/vulnerability/november-2020-security-releases/https://security.gentoo.org/glsa/202012-11https://security.gentoo.org/glsa/202101-07https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-11-19
Published