Intel

AIKIDO-2025-10179

trust-dns-proto is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 25, 2025

45

Medium Risk

This Affects:

Are you affected? Scan for Free

TL;DR

The trust-dns-proto package is no longer maintained, as its maintainers have renamed the repository to hickory-proto. Users should migrate to hickory-proto to ensure continued support and updates.

Who does this affect?

You are affected if you are using this package.

Background info

trust-dns-proto is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any trust-dns-proto package from your application. Please take a look at hickory-proto instead.