Intel

AIKIDO-2026-415253

hickory-proto is vulnerable to Improper Access Control

Improper Access ControlGHSA-4jwp-xjwm-333g Published 3 days ago

55

Medium Risk

This Affects:

RUSThickory-proto
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

Access-control checks compare client and server IP addresses without canonicalizing IPv4-mapped IPv6 addresses first. The same underlying IPv4 address expressed as an IPv4-mapped IPv6 address is treated as a distinct address, so allow lists, deny lists, and do-not-query filters can be bypassed. The fix canonicalizes addresses before matching.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you rely on IP allow/deny lists, do-not-query filters, or client access control

Background info

hickory-proto is vulnerable to Improper Access Control in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-proto library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform