Impact
hickory-resolver versions before 0.26.2 do not propagate bogus DNSSEC proof states through its lookup APIs, causing forged responses to be accepted as valid. This flaw is a CWE‑354 example of improper handling of edge cases, allowing attackers to supply malicious DNS records that appear authenticated. As a result, an adversary controlling an authoritative zone or intercepting DNS traffic can redirect clients, facilitate phishing, or perform man‑in‑the‑middle attacks without requiring local privileges on the resolver.
Affected Systems
The vulnerability affects all releases of hickory-dns/hickory-resolver older than 0.26.2. Any deployment that uses one of these versions, regardless of operating system or platform, is vulnerable if it relies on the resolver’s DNSSEC validation logic. The risk is mitigated only when a newer version is run or when network controls override the resolver’s behavior.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity flaw. The EPSS score is below 1%, indicating a very low but non‑zero probability that this vulnerability will be actively exploited. The flaw is not listed in the CISA KEV catalog. The likely attack vector is straightforward: an attacker who can modify zone data or inject traffic on the network path can exploit the absence of proof propagation. No elevated rights or local access are required; the flaw can be leveraged remotely. Until a fixed version is installed, the potential for widespread compromise exists, especially in environments that depend on DNSSEC for trust validation.
OpenCVE Enrichment