GHSA-5j98-2g5x-46v6HighCVSS 7.5Disclosed before NVD

hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures

Published
October 5, 2026
Last Modified
October 5, 2026

📋 Description

When calling Resolver::lookup() or Resolver::lookup_ip() on a resolver with DNSSEC validation enabled, both methods return Ok(...) if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.

🎯 Affected products1

  • rust/hickory-resolver:< 0.26.2

🔗 References (5)