GHSA-5j98-2g5x-46v6: High severity rust/hickory-resolver vulnerability

Published Oct 5, 2026
·
Updated

When calling Resolver::lookup() or Resolver::lookupip() on a resolver with DNSSEC validation enabled, both methods return Ok(...) if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.

Affected Software

1 affected componentFixes available
rust/hickory-resolver<0.26.2
0.26.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/hickory-resolver to a version that resolves this vulnerability.

    Fixed in 0.26.2

Event History

Oct 5, 2026
Advisory Published
via GitHub·10:54 PM
Data Sourced
via GitHub·10:54 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using rust/hickory-resolver that enable DNSSEC validation and call Resolver::lookup() or Resolver::lookup_ip() are affected. The risk is greatest where callers treat an Ok result as confirmation that DNSSEC validation succeeded.

2

What does an attacker need to exploit this issue?

The supplied severity vector indicates network attack access, low attack complexity, no required privileges, and no user interaction. The issue is relevant when DNSSEC validation identifies a response as bogus but the lookup API still returns Ok.

3

Can an application detect the validation failure despite receiving Ok?

Yes, the validation status of individual records can be checked, but the advisory describes doing so as very inconvenient. The affected lookup methods themselves do not return an error when validation determines the response is bogus.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203