Vulnerability GHSA-5j98-2g5x-46v6

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 hours ago
October 05, 2026 at 10:54 PM UTC
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
0.1.0 - 0.24.4 and 0.25.0 - 0.25.2 and 0.26.0 - 0.26.1
0.1.0 - 0.24.4 and 0.25.0 - 0.25.2 and 0.26.0 - 0.26.1

Summary

hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures

Details

When calling Resolver::lookup() or Resolver::lookup_ip() on a resolver with DNSSEC validation enabled, both methods return Ok(...) if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.

Impacted packages

Timeline

Published
8 hours ago
October 05, 2026 at 10:54 PM UTC
Fixed (0.26.2)
1 month ago
September 03, 2026 at 07:35 PM UTC
Last Modified
8 hours ago
October 05, 2026 at 11:00 PM UTC