
Cloud Vulnerability DB
A community-led vulnerabilities database
Hickory DNS, a Rust-based DNS client, server, and resolver, contains a vulnerability (CVE-2025-25188) affecting versions from 0.8.0 up to versions 0.24.3 and 0.25.0-alpha.5. The vulnerability impacts users relying on DNSSEC verification in the client library, stub resolver, or recursive resolver. The issue was discovered and reported by divergentdave, and has been assigned a CVSS v4.0 score of 5.7 (Medium) (GitHub Advisory).
The vulnerability lies in the DNSSEC validation routines which incorrectly treat entire RRsets of DNSKEY records as trusted after establishing trust in only one of the DNSKEYs. This creates two variants of the vulnerability: first, if a zone includes a DNSKEY with a public key matching a configured trust anchor, all keys in that zone are trusted to authenticate other records; second, an authenticated DS record covering one DNSKEY leads to trust in signatures made by an unrelated DNSKEY in the same zone (GitHub Advisory).
The vulnerability could allow an attacker to bypass DNSSEC verification mechanisms, potentially leading to the acceptance of broken authentication chains. This affects the security of DNS resolution and validation processes, particularly in environments where DNSSEC verification is relied upon for security (GitHub Advisory).
The vulnerability has been fixed in versions 0.24.3 and 0.25.0-alpha.5. Users are advised to upgrade to these or newer versions. The fix involves proper validation of DNSKEY RRsets and verification of authentication chains (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."