ThreatCluster

Multiple Vulnerabilities in c-ares Library Announced

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Two vulnerabilities in the c-ares library were reported on February 18, 2026. CVE-2023-31130, a buffer underwrite issue, was published on May 25, 2023, while CVE-2020-22217, a buffer overflow vulnerability, was published on August 22, 2023. Affected versions include c-ares prior to 1.16.1 and through 1.17.0.

Timeline

2023-05-25
CVE-2023-31130 published
2023-08-22
CVE-2020-22217 published
2026-02-18
Information published about both vulnerabilities