GHSA-5j98-2g5x-46v6

Suggest an improvement
Source
https://github.com/advisories/GHSA-5j98-2g5x-46v6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-5j98-2g5x-46v6/GHSA-5j98-2g5x-46v6.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-5j98-2g5x-46v6
Aliases
Published
2026-10-05T22:54:35Z
Modified
2026-10-05T23:00:04Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
Details

When calling Resolver::lookup() or Resolver::lookup_ip() on a resolver with DNSSEC validation enabled, both methods return Ok(...) if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.

Database specific
{
    "cwe_ids":  [
        "CWE-347"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T22:54:35Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

crates.io / hickory-resolver

Package

Name
hickory-resolver
View open source insights on deps.dev
Purl
pkg:cargo/hickory-resolver

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.26.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-5j98-2g5x-46v6/GHSA-5j98-2g5x-46v6.json"