hickory-net is vulnerable to Improper Verification of Cryptographic Signature
30
Low Risk
During DNSSEC validation, public keys are compared against configured trust anchors without regard for the DNSKEY record's owner name. If every DNSKEY in an RRset is a trusted key, verification succeeds without checking any RRSIGs. This lets a secure zone's DNSKEY RRset be replaced with the root zone's keys without detection, and a large TTL can extend the effect. The fix checks the DNSKEY name against the trust anchor.
You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled
hickory-net is vulnerable to Improper Verification of Cryptographic Signature in versions 0.26.0 - 0.26.1.
Upgrade the hickory-net library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.