hickory-resolver is vulnerable to DNS Cache Poisoning
55
Medium Risk
When a client sends apex NS queries for a zone, the recursor caches the zone's apex NS RRset and later reuses it during iterative resolution. Repeated queries can keep the RRset in cache indefinitely. If the parent zone changes or removes the delegation, the recursor may keep using the old name servers, letting the previous operators control responses after their referral was revoked. This is a ghost-domain attack. The fix limits reuse of cached child-side NS RRsets.
You are affected if you are using a version that falls within the vulnerable range and you use the recursive resolver
hickory-resolver is vulnerable to DNS Cache Poisoning in versions 0.26.0 - 0.26.1.
Upgrade the hickory-resolver library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.