MajorCritical vulnerability
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
GitHub Advisories · officialPublished Oct 5, 2026Risk 37/100
When calling `Resolver::lookup()` or `Resolver::lookup_ip()` on a resolver with DNSSEC validation enabled, both methods return `Ok(...)` if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.
Recommended action
Recommended action
Upgrade affected packages to a patched version: hickory-resolver 0.26.2.
Technical details
- Vendor
- Not specified
- Product
- hickory-resolver
- Exploitation
- none known
- Evidence
- official
CVSS
7.5
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source