DNSSEC Validation Bypass in Hickory-Resolver by Hickory DNS
CVE-2026-93657
8.7HIGH
What is CVE-2026-93657?
The hickory-resolver software prior to version 0.26.2 contains a vulnerability that allows attackers to exploit the DNSSEC validation process. Specifically, the Resolver::lookup() and Resolver::lookup_ip() APIs fail to properly handle invalid DNSSEC proof states, permitting malicious actors who control the answering DNS zone or are positioned on the network to inject forged DNS records. This results in these invalid records being accepted as legitimate, thereby circumventing standard DNSSEC authentication mechanisms. Users are advised to upgrade to version 0.26.2 to mitigate this issue.
Affected Version(s)
hickory-resolver 0 < 0.26.2
hickory-resolver 0.26.2
