Intel

AIKIDO-2026-511238

hickory-resolver is vulnerable to DNS Cache Poisoning

DNS Cache PoisoningGHSA-vcjp-57rr-mpfw Published 3 days ago

50

Medium Risk

This Affects:

RUSThickory-resolver
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

The recursive resolver applies out-of-bailiwick filtering to positive responses but not to negative responses. Records outside the queried zone's bailiwick in a negative response are therefore accepted and cached. This weakens a defense against cache poisoning and can make other DNSSEC validation weaknesses easier to exploit. The fix applies bailiwick filtering to negative responses as well.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the recursive resolver

Background info

hickory-resolver is vulnerable to DNS Cache Poisoning in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-resolver library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform