Description
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
Remediation
References
Related Vulnerabilities
Tornado Improper Handling of Invalid Use of Special Elements Vulnerability (CVE-2026-35536)
WordPress Plugin Login/Signup Popup (Inline Form + Woocommerce) Security Bypass (2.7.2)
Drupal Core 7.x Remote Code Execution (7.0 - 7.58)
MyBB URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-20225)