PT-2026-95426 · Unknown · Hickory-Resolver

·

CVE-2026-93657

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions hickory-resolver versions prior to 0.26.2
Description The software fails to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup ip() APIs, which allows invalid records to be returned as successful results. This issue enables attackers who control the answering zone or are positioned on the network path to have forged DNS records accepted as validated, effectively bypassing DNSSEC authentication checks.
Recommendations Update to version 0.26.2 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93657
GHSA-5J98-2G5X-46V6

Affected Products

Hickory-Resolver