Intel

AIKIDO-2026-634473

hickory-net is vulnerable to Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic SignatureGHSA-j2rc-wxwh-62g9 Published 3 days ago

30

Low Risk

This Affects:

RUSThickory-net
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

During DNSSEC validation, public keys are compared against configured trust anchors without regard for the DNSKEY record's owner name. If every DNSKEY in an RRset is a trusted key, verification succeeds without checking any RRSIGs. This lets a secure zone's DNSKEY RRset be replaced with the root zone's keys without detection, and a large TTL can extend the effect. The fix checks the DNSKEY name against the trust anchor.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled

Background info

hickory-net is vulnerable to Improper Verification of Cryptographic Signature in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-net library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform