Executive brief
hickory-resolver is a Rust-based DNS resolver library used by applications to perform secure domain name lookups. A flaw in versions before 0.26.2 causes the resolver to incorrectly accept forged DNS records that should have failed DNSSEC validation, potentially allowing attackers to redirect users to malicious sites or intercept communications if they control the DNS zone or network path.
Technical details
The vulnerability is a DNSSEC validation bypass in the Resolver::lookup() and Resolver::lookup_ip() API methods. The root cause is a failure to properly propagate bogus DNSSEC proof states up through the resolver's call chain, resulting in invalid DNS records being returned as if they passed validation. An attacker positioned on the network or controlling an authoritative zone can exploit this by presenting forged DNS records. The vulnerability requires no authentication or user interaction; exploitation is possible via direct DNS queries. The fix is available in hickory-resolver version 0.26.2 and later.
Affected products
- hickory-dns hickory-resolver before 0.26.2
Timeline
- 2026-09-18: disclosed