Intel

AIKIDO-2026-253642

hickory-net is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-xv7c-h5g9-x25x Published 3 days ago

30

Low Risk

This Affects:

RUSThickory-net
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

A logic error in the DS-fetch path of DNSSEC validation treats a transient, single failed DS lookup as a durable bogus verdict for an entire child zone. That synthetic bogus result is cached, so later validations short-circuit and return SERVFAIL without re-querying the parent for DS records. Resolution of the affected zone stays broken until the cache entry expires. The fix stops caching transient DS-fetch failures as bogus.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled

Background info

hickory-net is vulnerable to Denial of Service (DoS) in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-net library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform