Vulnerability GHSA-5j98-2g5x-46v6
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 hours ago
October 05, 2026 at 10:54 PM UTC
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
0.1.0 - 0.24.4 and 0.25.0 - 0.25.2 and 0.26.0 - 0.26.1
0.1.0 - 0.24.4 and 0.25.0 - 0.25.2 and 0.26.0 - 0.26.1
Summary
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
Details
When calling Resolver::lookup() or Resolver::lookup_ip() on a resolver with DNSSEC validation enabled, both methods return Ok(...) if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
8 hours ago
hickory-resolver follows irrelevant CNAME records
0.25.0 - 0.25.2 and 0.26.0 - 0.26.1 GHSA-6f2x-v7q7-m7m5
0.25.0 - 0.25.2 and 0.26.0 - 0.26.1 GHSA-6f2x-v7q7-m7m5
High Risk
8 hours ago
hickory-resolver: Unbounded TC-retry loop in `NameServerPool::try_send` (resource-exhaustion DoS)
0.26.0-beta.1 - 0.26.1 GHSA-6w6g-hm98-mhgm
0.26.0-beta.1 - 0.26.1 GHSA-6w6g-hm98-mhgm
Impacted packages
Timeline
Published
8 hours ago
October 05, 2026 at 10:54 PM UTC
Fixed (0.26.2)
1 month ago
September 03, 2026 at 07:35 PM UTC
Last Modified
8 hours ago
October 05, 2026 at 11:00 PM UTC