CVE-2026-93657 PUBLISHED

hickory-resolver before 0.26.2 DNSSEC Validation Bypass

Assigner: VulnCheck
Reserved: 18.09.2026 Published: 18.09.2026 Updated: 18.09.2026

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor hickory-dns
Product hickory-resolver
Versions Default: unaffected
  • affected from 0 to 0.26.2 (excl.)
  • Version 0.26.2 is unaffected

Credits

  • Ali Firas (thesmartshadow) finder

References

Problem Types

  • Improper Verification of Cryptographic Signature CWE