DNSSEC Validation Bypass in Hickory-Resolver by Hickory DNS
CVE-2026-93657

8.7HIGH

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93657?

The hickory-resolver software prior to version 0.26.2 contains a vulnerability that allows attackers to exploit the DNSSEC validation process. Specifically, the Resolver::lookup() and Resolver::lookup_ip() APIs fail to properly handle invalid DNSSEC proof states, permitting malicious actors who control the answering DNS zone or are positioned on the network to inject forged DNS records. This results in these invalid records being accepted as legitimate, thereby circumventing standard DNSSEC authentication mechanisms. Users are advised to upgrade to version 0.26.2 to mitigate this issue.

Affected Version(s)

hickory-resolver 0 < 0.26.2

hickory-resolver 0.26.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Firas (thesmartshadow)
.