Intel

AIKIDO-2026-702261

hickory-resolver is vulnerable to DNS Cache Poisoning

DNS Cache PoisoningGHSA-2hxp-x833-73f7 Published 3 days ago

55

Medium Risk

This Affects:

RUSThickory-resolver
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

When a client sends apex NS queries for a zone, the recursor caches the zone's apex NS RRset and later reuses it during iterative resolution. Repeated queries can keep the RRset in cache indefinitely. If the parent zone changes or removes the delegation, the recursor may keep using the old name servers, letting the previous operators control responses after their referral was revoked. This is a ghost-domain attack. The fix limits reuse of cached child-side NS RRsets.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the recursive resolver

Background info

hickory-resolver is vulnerable to DNS Cache Poisoning in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-resolver library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform