highCVSS 7.5Vulnerability
GHSA-5j98-2g5x-46v6
When calling `Resolver::lookup()` or `Resolver::lookup_ip()` on a resolver with DNSSEC validation enabled, both methods return `Ok(...)` if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.
Properties
- summary
- hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
- severity
- high
- cvss_score
- 7.5
- retrieved_at
- 2026-10-06T03:05:59+00:00
- ghsa_published
- 2026-10-05T22:54:35Z
- source_url
- https://github.com/advisories/GHSA-5j98-2g5x-46v6
- ghsa_updated
- 2026-10-05T22:54:37Z
- ghsa_id
- GHSA-5j98-2g5x-46v6
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-5j98-2g5x-46v6
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- signal_observed_at
- 2026-10-06T02:58:31+00:00
- is_ghsa_only
- true
Related Entities (4)
HAS_WEAKNESS (1)
→[Weakness]Improper Verification of Cryptographic Signature
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]rust/hickory-resolver
AFFECTS (1)
→[Software]rust/hickory-resolver
Explore deeper with Ninja Signal's threat intelligence graph