Description
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: DNSSEC validation bypass
Action: Patch
AI Analysis

Impact

hickory-resolver versions before 0.26.2 do not propagate bogus DNSSEC proof states through its lookup APIs, causing forged responses to be accepted as valid. This flaw is a CWE‑354 example of improper handling of edge cases, allowing attackers to supply malicious DNS records that appear authenticated. As a result, an adversary controlling an authoritative zone or intercepting DNS traffic can redirect clients, facilitate phishing, or perform man‑in‑the‑middle attacks without requiring local privileges on the resolver.

Affected Systems

The vulnerability affects all releases of hickory-dns/hickory-resolver older than 0.26.2. Any deployment that uses one of these versions, regardless of operating system or platform, is vulnerable if it relies on the resolver’s DNSSEC validation logic. The risk is mitigated only when a newer version is run or when network controls override the resolver’s behavior.

Risk and Exploitability

The CVSS score of 8.7 classifies this as a high‑severity flaw. The EPSS score is below 1%, indicating a very low but non‑zero probability that this vulnerability will be actively exploited. The flaw is not listed in the CISA KEV catalog. The likely attack vector is straightforward: an attacker who can modify zone data or inject traffic on the network path can exploit the absence of proof propagation. No elevated rights or local access are required; the flaw can be leveraged remotely. Until a fixed version is installed, the potential for widespread compromise exists, especially in environments that depend on DNSSEC for trust validation.

Generated by OpenCVE AI on September 23, 2026 at 01:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update hickory-resolver to version 0.26.2 or later to apply the DNSSEC proof propagation fix.
  • If an update cannot be applied immediately, replace the resolver with a DNS service that performs full DNSSEC validation and configure it to reject any responses lacking trusted signatures.
  • Apply network controls such as firewall rules or DNS over TLS to limit exposure to attackers controlling authoritative zones or intercepting DNS traffic, and monitor for anomalous responses.

Generated by OpenCVE AI on September 23, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-354
References
Metrics threat_severity

None

threat_severity

Important


Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Hickory-dns
Hickory-dns hickory-resolver
Vendors & Products Hickory-dns
Hickory-dns hickory-resolver

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
Title hickory-resolver before 0.26.2 DNSSEC Validation Bypass
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Hickory-dns Hickory-resolver
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:51:40.507Z

Reserved: 2026-09-18T13:30:25.560Z

Link: CVE-2026-93657

cve-icon Vulnrichment

Updated: 2026-09-21T16:28:50.433Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T15:17:22.190

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-93657

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T14:23:20Z

Links: CVE-2026-93657 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:45:19Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature

  • CWE-354

    Improper Validation of Integrity Check Value