Intel

AIKIDO-2026-24248

hickory-server is vulnerable to Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic SignatureGHSA-8hq4-5836-w6q4 Published 3 days ago

55

Medium Risk

This Affects:

RUSThickory-server
0.25.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

When the validating recursive resolver and forwarder assemble NXDOMAIN or NODATA responses, they do not check whether the SOA record in the authority section passed DNSSEC validation. A forged SOA record can therefore be returned to clients in a response with the authenticated-data bit set. The impact affects clients that rely on the server for validation and use the SOA contents. The fix checks the SOA validation status before setting AD.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run the validating recursive resolver or forwarder and clients trust its AD bit

Background info

hickory-server is vulnerable to Improper Verification of Cryptographic Signature in versions 0.25.0 - 0.26.1.

How to fix this

Upgrade the hickory-server library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform