hickory-resolver is vulnerable to Improper Verification of Cryptographic Signature
75
High Risk
With DNSSEC validation enabled, the resolver's lookup and lookup_ip APIs return a successful result even when validation determines the response is bogus. Callers must inspect per-record proof status, which is inconvenient and easy to miss, so bogus data is treated as valid. These APIs should return an error for bogus responses. The fix makes them surface validation failures as errors.
You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled and use the lookup or lookup_ip APIs
hickory-resolver is vulnerable to Improper Verification of Cryptographic Signature in versions 0.24.0 - 0.26.1.
Upgrade the hickory-resolver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.