CVE Tools

C-ares

19 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for C-ares, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

C-ares CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
C-ares CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-093

Severity

How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical15%
  • High842%
  • Medium842%
  • Low211%

Latest CVEs

The 15 most recently published vulnerabilities affecting C-ares.

  1. CVE-2026-69184c-ares: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains7.5
  2. CVE-2026-69186c-ares: Memory-amplification denial of service via unvalidated DNS header record counts5.3
  3. CVE-2026-33630c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP7.5
  4. CVE-2025-62408c-ares has a Use After Free vulnerability when connection is cleaned up after error5.9
  5. CVE-2025-31498c-ares has a use-after-free in read_answers()7.0
  6. CVE-2024-25629c-ares out of bounds read in ares__read_line()4.4
  7. CVE-2020-22217Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.5.9
  8. CVE-2023-320670-byte UDP payload DoS in c-ares7.5
  9. CVE-2023-31147Insufficient randomness in generation of DNS query IDs in c-ares5.9
  10. CVE-2023-31130Buffer Underwrite in ares_inet_net_pton()4.1
  11. CVE-2023-31124AutoTools does not set CARES_RANDOM_FILE during cross compilation3.7
  12. CVE-2022-4904A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause...8.6
  13. CVE-2021-3672A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to ...5.6
  14. CVE-2020-14354A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service...3.3
  15. CVE-2020-8277A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the app...7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store