CVE-2026-42254 Details
Description
Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.
A cross-zone poisoning vulnerability has been identified in Hickory DNS hickory-recursor versions 0.1 through 0.25.2. The issue arises because the record cache does not associate cached data with the specific query that triggered the response. Instead, records are stored based on their own attributes, allowing for the injection of false information from one zone into another. This can misdirect DNS queries to an attacker's nameserver, bypassing the legitimate one.
Users should update to Hickory DNS resolver version 0.26.0 or later, with the 'recursor' feature enabled. The 'hickory-recursor' crate will not receive further updates, so all users should migrate to 'hickory-resolver'.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-83hf-93m4-rgwq | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-706 | Use of Incorrectly-Resolved Name or Reference | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 26, 2026 | New CVE Received | [email protected] |