Intel

AIKIDO-2026-751352

hickory-net is vulnerable to DNS Spoofing

DNS SpoofingGHSA-3w89-7rx5-hpwx Published 3 days ago

37

Low Risk

This Affects:

RUSThickory-net
0.26.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

On a client UDP connection, a response whose question section is empty (QDCOUNT of zero) skips the check that the response question matches the query. When case randomization is enabled, the matching-capitalization check is skipped as well. This removes a layer of defense in depth against off-path spoofing. The fix rejects responses that do not carry the expected question section.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

hickory-net is vulnerable to DNS Spoofing in versions 0.26.0 - 0.26.1.

How to fix this

Upgrade the hickory-net library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform