Intel

AIKIDO-2026-350959

hickory-resolver is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-29q9-p769-j8gq Published 3 days ago

30

Low Risk

This Affects:

RUSThickory-resolver
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

DNSSEC-bogus answers are cached using the record TTL from the unauthenticated response, bounded only by 24 hours. Because that TTL is not trustworthy, a crafted invalidly signed response can pin a bogus verdict in the cache for a long time. Subsequent queries for the same name keep failing until the entry expires. The fix caps cached validation failures at a small TTL.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you enable DNSSEC validation.

Background info

hickory-resolver is vulnerable to Denial of Service (DoS) in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-resolver and/or the hickory-net library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform