Intel

AIKIDO-2026-982976

hickory-proto is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-wgfr-mphw-j5g4 Published 3 days ago

65

Medium Risk

This Affects:

RUSThickory-proto
0.24.0 - 0.26.1
Fixed in 0.26.2
Are you affected? Scan for Free

TL;DR

The presentation-format parser for SVCB and HTTPS records mishandles a service parameter value that consists solely of a single quote character. It slices the value as if surrounding quotes were present, which panics on the malformed input. Systems that parse untrusted zone files can be crashed. The fix validates quoting before slicing.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you parse untrusted zone files

Background info

hickory-proto is vulnerable to Denial of Service (DoS) in versions 0.24.0 - 0.26.1.

How to fix this

Upgrade the hickory-proto library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform