hickory-resolver is vulnerable to DNS Cache Poisoning
50
Medium Risk
The recursive resolver applies out-of-bailiwick filtering to positive responses but not to negative responses. Records outside the queried zone's bailiwick in a negative response are therefore accepted and cached. This weakens a defense against cache poisoning and can make other DNSSEC validation weaknesses easier to exploit. The fix applies bailiwick filtering to negative responses as well.
You are affected if you are using a version that falls within the vulnerable range and you use the recursive resolver
hickory-resolver is vulnerable to DNS Cache Poisoning in versions 0.26.0 - 0.26.1.
Upgrade the hickory-resolver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.