CVE-2026-42254
Received
Received - Intake
Cross-Zone Poisoning in Hickory DNS Recursor
Publication date: 2026-04-26
Last updated on: 2026-04-26
Assigner: MITRE
Description
Description
Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hickory_dns | hickory_recursor | From 0.1 (inc) to 0.25.2 (inc) |
| hickory_dns | hickory_resolver | 0.26.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-706 | The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere. |