File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -27,4 +27,16 @@ ignore = [
2727 # logger calls `rand::rng()` during reseeding. Our 0.8.5 (transitive via alloy-consensus)
2828 # has neither feature enabled; our 0.9.4 is already patched.
2929 " RUSTSEC-2026-0097" ,
30+
31+ # `hickory-proto` 0.25.2 NSEC3 closest-encloser proof validation unbounded loop on cross-zone
32+ # responses. No fixed upgrade is available. Transitive dep via reth's `reth-dns-discovery` ->
33+ # `hickory-resolver`. node-components does not perform DNSSEC validation, so this code path is
34+ # unused.
35+ " RUSTSEC-2026-0118" ,
36+
37+ # `hickory-proto` 0.25.2 O(n²) name-compression CPU exhaustion during message encoding. Fix is
38+ # in 0.26.1, but `hickory-resolver` 0.25.2 (pinned by reth's `reth-dns-discovery`) requires
39+ # `hickory-proto ^0.25`, so we can't upgrade until reth bumps. node-components does not encode
40+ # DNS messages.
41+ " RUSTSEC-2026-0119" ,
3042]
You can’t perform that action at this time.
0 commit comments