Intel

AIKIDO-2026-278403

hickory-resolver is vulnerable to Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic SignatureGHSA-5j98-2g5x-46v6 Published 3 days ago

75

High Risk

This Affects:

RUSThickory-resolver
0.24.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

With DNSSEC validation enabled, the resolver's lookup and lookup_ip APIs return a successful result even when validation determines the response is bogus. Callers must inspect per-record proof status, which is inconvenient and easy to miss, so bogus data is treated as valid. These APIs should return an error for bogus responses. The fix makes them surface validation failures as errors.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled and use the lookup or lookup_ip APIs

Background info

hickory-resolver is vulnerable to Improper Verification of Cryptographic Signature in versions 0.24.0 - 0.26.1.

How to fix this

Upgrade the hickory-resolver library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform