CVE-2026-93657

high

Description

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.

References

https://www.vulncheck.com/advisories/hickory-resolver-before-0.26.2-dnssec-validation-bypass

https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6

https://github.com/hickory-dns/hickory-dns/releases/tag/v0.26.2

https://github.com/hickory-dns/hickory-dns/pull/3871

https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274ea4a9fdd238

https://github.com/hickory-dns/hickory-dns

Details

Source: Mitre, NVD

Published: 2026-09-18

Updated: 2026-09-18

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High

CVSS v4

Base Score: 8.7

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.0023