Intel

AIKIDO-2026-222296

hickory-net is vulnerable to Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic SignatureGHSA-rx82-4p2j-j5cv Published 3 days ago

50

Medium Risk

This Affects:

RUSThickory-net
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

The DNSSEC validation cache keys entries on a 64-bit hash of the owner name, and the name hash ignores label boundaries so names that differ only in dot placement collide. A collision lets a benign insecure verdict for one name be reused for a different target name, so validation is skipped and forged data is returned as an insecure answer (AD=0). The differing hash and equality behavior also enables hash-collision denial of service. The fix makes the name hash and cache key collision-resistant.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled

Background info

hickory-net is vulnerable to Improper Verification of Cryptographic Signature in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-net library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform