hickory-net is vulnerable to Improper Verification of Cryptographic Signature
59
Medium Risk
The NSEC3 handler selects the closest encloser by hash equality alone and never inspects the type bitmap, so a parent-side ancestor-delegation NSEC3 at a zone cut is accepted as proof for names below the cut. The no-data arm has the same defect, authenticating absence of non-DS types at the cut owner. Using only genuinely signed parent records, an adversary can forge authenticated NXDOMAIN for names that exist in the child zone. The fix applies the ancestor-delegation exclusion.
You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled
hickory-net is vulnerable to Improper Verification of Cryptographic Signature in versions 0.26.0 - 0.26.1.
Upgrade the hickory-net library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.