hickory-resolver is vulnerable to Denial of Service (DoS)
30
Low Risk
DNSSEC-bogus answers are cached using the record TTL from the unauthenticated response, bounded only by 24 hours. Because that TTL is not trustworthy, a crafted invalidly signed response can pin a bogus verdict in the cache for a long time. Subsequent queries for the same name keep failing until the entry expires. The fix caps cached validation failures at a small TTL.
You are affected if you are using a version that falls within the vulnerable range and you enable DNSSEC validation.
hickory-resolver is vulnerable to Denial of Service (DoS) in versions 0.26.0 - 0.26.1.
Upgrade the hickory-resolver and/or the hickory-net library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.