This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate hickory-server

Dependencies

(24 total, 12 outdated, 3 insecure)

CrateRequiredLatestStatus
 async-trait^0.1.430.1.92up to date
 basic-toml^0.10.1.10up to date
 bytes^11.12.1up to date
 cfg-if^11.0.5up to date
 enum-as-inner^0.60.7.0out of date
 futures-util^0.3.50.3.34up to date
 h2 ⚠️^0.3.00.4.19insecure
 h3^0.0.20.0.8out of date
 h3-quinn^0.0.30.0.10out of date
 hickory-proto ⚠️^0.24.00.26.3insecure
 hickory-recursor ⚠️^0.24.00.25.2insecure
 hickory-resolver^0.24.00.26.3out of date
 http^0.21.5.0out of date
 openssl^0.10.550.10.81up to date
 rusqlite^0.310.40.2out of date
 rustls^0.21.60.23.45out of date
 serde^1.01.0.229up to date
 thiserror^1.0.202.0.21out of date
 time^0.30.3.55up to date
 tokio^1.211.53.2up to date
 tokio-openssl^0.6.00.6.5up to date
 tokio-rustls^0.24.00.26.6out of date
 tokio-util^0.7.90.7.19up to date
 tracing^0.1.300.1.44up to date

Dev dependencies

(3 total, all up-to-date)

CrateRequiredLatestStatus
 futures-executor^0.3.50.3.34up to date
 tokio^1.211.53.2up to date
 tracing-subscriber^0.30.3.23up to date

Security Vulnerabilities

hickory-recursor: Record cache accepts AUTHORITY section NS from sibling zone via parent-pool zone-context elevation

RUSTSEC-2026-0106

The Hickory DNS project's experimental hickory-recursor crate's record cache (DnsLru) stores records from DNS responses keyed by each record's own (name, type), not by the query that triggered the response. cache_response() in crates/recursor/src/lib.rs chains ANSWER, AUTHORITY, and ADDITIONAL sections into one record iterator before insertion. The bailiwick filter it applies uses the zone context of the NS pool that serviced the lookup, not the zone being queried.

This creates a cross-zone poisoning path. When Hickory builds the NS pool for attacker.poc. it uses the parent poc. NS pool (ns.zone() = "poc."). If the poc. nameserver under the attacker's control includes in its response's AUTHORITY section a record for a sibling zone like victim.poc. NS ns.evil.poc., the bailiwick check is_subzone("poc.", "victim.poc.") passes (victim.poc. is a subdomain of poc.). The record is stored under (victim.poc., NS) in the shared cache.

Subsequently, any client querying a name in victim.poc. causes Hickory to build its NS pool from the poisoned cache entry, routing queries to the attacker's nameserver (ns.evil.poc.) rather than to the legitimate nameserver for victim.poc.. The legitimate NS for that zone receives zero queries.

This issue is fixed in hickory-resolver 0.26.0 with the recursor feature through an architectural change to response-level caching: responses are stored keyed by the originating query (name, type). A response to (attacker.poc. NS) is stored only under that key and cannot affect the (victim.poc., NS) cache entry.

We believe this issue has been present in all published versions of the experimental hickory-recursor crate, which has now been folded into the hickory-resolver crate under the non-default recursor feature flag. The hickory-recursor crate will not receive any updates going forward and all users should migrate to hickory-resolver with the recursor feature.

hickory-proto: CPU exhaustion during message encoding due to O(n²) name compression

RUSTSEC-2026-0119

During message encoding, hickory-proto's BinEncoder stores pointers to labels that are candidates for name compression in a Vec<(usize, Vec<u8>)>. The name compression logic then searches for matches with a linear scan.

A malicious message with many records can both introduce many candidate labels, and invoke this linear scan many times. This can amplify CPU exhaustion in DoS attacks.

This is similar to CVE-2024-8508.

We recommend all affected users update to hickory-proto 0.26.1 for the fix.

h2: h2 unbounded empty DATA frames

RUSTSEC-2026-0258

The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.

Low severity.

Patched in v0.4.16.