highCVSS 7.5Vulnerability

GHSA-5j98-2g5x-46v6

When calling `Resolver::lookup()` or `Resolver::lookup_ip()` on a resolver with DNSSEC validation enabled, both methods return `Ok(...)` if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.

Properties

summary
hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
severity
high
cvss_score
7.5
retrieved_at
2026-10-06T03:05:59+00:00
ghsa_published
2026-10-05T22:54:35Z
source_url
https://github.com/advisories/GHSA-5j98-2g5x-46v6
ghsa_updated
2026-10-05T22:54:37Z
ghsa_id
GHSA-5j98-2g5x-46v6
last_source
GitHub Advisory Database
cve_id
GHSA-5j98-2g5x-46v6
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
signal_observed_at
2026-10-06T02:58:31+00:00
is_ghsa_only
true

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Improper Verification of Cryptographic Signature

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]rust/hickory-resolver

AFFECTS (1)

→[Software]rust/hickory-resolver

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5j98-2g5x-46v6 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal