Memory Leak in Resolv Gem for Ruby Affects Memory Management
CVE-2026-80212

7.5HIGH

Key Information:

Vendor

Ruby

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-80212?

A severe memory leak issue has been identified in the Resolv gem in Ruby. The vulnerability arises when the gem’s methods respond to unknown DNS resource records generated through manipulated or hijacked DNS responses. This process leads to the permanent registration of new classes for each unknown resource type or parameter encountered during the decoding of exposed DNS messages. Consequently, these classes remain in memory indefinitely, causing significant memory consumption during repeated attacks, which can degrade system performance. Systems that utilize the Resolv gem are at risk, particularly with untrusted DNS data, raising concerns around stability and resource management.

Affected Version(s)

resolv 0 < 0.3.2

resolv 0.4.0 < 0.7.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.