{"id":"GHSA-5j98-2g5x-46v6","title":"hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures","summary":"hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures","severity":"high","cvss":7.5,"cwe":["CWE-347"],"vendor":"hickory-resolver","product":"hickory-resolver","ecosystem":"rust","affected":["hickory-resolver < 0.26.2"],"patched":["hickory-resolver 0.26.2"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T22:54:37Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-5j98-2g5x-46v6","references":[{"url":"https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6"},{"url":"https://github.com/hickory-dns/hickory-dns/pull/3871"},{"url":"https://github.com/hickory-dns/hickory-dns/commit/92f93c0b889f6a292bc943304d88c4c6561fe1b9"},{"url":"https://github.com/hickory-dns/hickory-dns/releases/tag/v0.26.2"},{"url":"https://github.com/advisories/GHSA-5j98-2g5x-46v6"}],"tags":["ghsa","rust"],"ingestedAt":"2026-10-05T23:36:21.172Z","slug":"GHSA-5j98-2g5x-46v6","body":"## Overview\n\nWhen calling `Resolver::lookup()` or `Resolver::lookup_ip()` on a resolver with DNSSEC validation enabled, both methods return `Ok(...)` if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.\n\n## Affected packages\n\n- `hickory-resolver < 0.26.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `hickory-resolver 0.26.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}