CVE-2025-25188
Rust vulnerability analysis and mitigation

Overview

Hickory DNS, a Rust-based DNS client, server, and resolver, contains a vulnerability (CVE-2025-25188) affecting versions from 0.8.0 up to versions 0.24.3 and 0.25.0-alpha.5. The vulnerability impacts users relying on DNSSEC verification in the client library, stub resolver, or recursive resolver. The issue was discovered and reported by divergentdave, and has been assigned a CVSS v4.0 score of 5.7 (Medium) (GitHub Advisory).

Technical details

The vulnerability lies in the DNSSEC validation routines which incorrectly treat entire RRsets of DNSKEY records as trusted after establishing trust in only one of the DNSKEYs. This creates two variants of the vulnerability: first, if a zone includes a DNSKEY with a public key matching a configured trust anchor, all keys in that zone are trusted to authenticate other records; second, an authenticated DS record covering one DNSKEY leads to trust in signatures made by an unrelated DNSKEY in the same zone (GitHub Advisory).

Impact

The vulnerability could allow an attacker to bypass DNSSEC verification mechanisms, potentially leading to the acceptance of broken authentication chains. This affects the security of DNS resolution and validation processes, particularly in environments where DNSSEC verification is relied upon for security (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in versions 0.24.3 and 0.25.0-alpha.5. Users are advised to upgrade to these or newer versions. The fix involves proper validation of DNSKEY RRsets and verification of authentication chains (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

RUSTSEC-2026-0216HIGH7.5
  • Rust logoRust
  • nostr
NoYesJul 25, 2026
GHSA-qqc3-94qv-7fw3MEDIUM6.3
  • Rust logoRust
  • hubuum_client
NoYesJul 24, 2026
GHSA-f45q-w629-wr25MEDIUM6.3
  • Rust logoRust
  • hubuum_client
NoYesJul 24, 2026
GHSA-g9hv-x236-4qp3MEDIUM5.3
  • Rust logoRust
  • russh
NoYesJul 24, 2026
GHSA-2625-rw7m-5q5xLOW2.3
  • Rust logoRust
  • hubuum_client
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management