Intel

AIKIDO-2026-564503

hickory-net is vulnerable to Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic SignatureGHSA-qw83-5pm2-ggp5 Published 3 days ago

89

High Risk

This Affects:

RUSThickory-net
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

DNSSEC verification identifies wraparound NSEC records, whose next domain name is the zone apex, by comparing the next domain name to the name of an SOA record in the response. That check is spoofable because a crafted, unvalidated SOA record can be included in the response and is accepted. As a result, a genuine NSEC record, its RRSIG, and a crafted SOA can forge nonexistence of any RRset. The fix identifies wraparound NSEC records by comparing owner name to next domain name.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled

Background info

hickory-net is vulnerable to Improper Verification of Cryptographic Signature in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-net library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform