---
id: GHSA-5j98-2g5x-46v6
title: >-
  hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure
  DNSSEC validation failures
summary: >-
  hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure
  DNSSEC validation failures
severity: high
cvss: 7.5
cwe:
  - CWE-347
vendor: hickory-resolver
product: hickory-resolver
ecosystem: rust
affected:
  - hickory-resolver < 0.26.2
patched:
  - hickory-resolver 0.26.2
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T22:54:37Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-5j98-2g5x-46v6'
references:
  - url: >-
      https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6
  - url: 'https://github.com/hickory-dns/hickory-dns/pull/3871'
  - url: >-
      https://github.com/hickory-dns/hickory-dns/commit/92f93c0b889f6a292bc943304d88c4c6561fe1b9
  - url: 'https://github.com/hickory-dns/hickory-dns/releases/tag/v0.26.2'
  - url: 'https://github.com/advisories/GHSA-5j98-2g5x-46v6'
tags:
  - ghsa
  - rust
ingestedAt: '2026-10-05T23:36:21.172Z'
---

## Overview

When calling `Resolver::lookup()` or `Resolver::lookup_ip()` on a resolver with DNSSEC validation enabled, both methods return `Ok(...)` if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.

## Affected packages

- `hickory-resolver < 0.26.2`

## Remediation

Upgrade to a patched release:

- `hickory-resolver 0.26.2`
