Vulnerability Description
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/hickory-dns/hickory-dns
- https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274e
- https://github.com/hickory-dns/hickory-dns/pull/3871
- https://github.com/hickory-dns/hickory-dns/releases/tag/v0.26.2
- https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46
- https://www.vulncheck.com/advisories/hickory-resolver-before-0.26.2-dnssec-valid
FAQ
What is CVE-2026-93657?
CVE-2026-93657 is a vulnerability with a CVSS score of 7.5 (HIGH). hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful...
How severe is CVE-2026-93657?
CVE-2026-93657 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-93657?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.