hickory-resolver: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
High severity
GitHub Reviewed
Published
Sep 3, 2026
in
hickory-dns/hickory-dns
•
Updated Oct 5, 2026
Description
Published to the GitHub Advisory Database
Oct 5, 2026
Reviewed
Oct 5, 2026
Last updated
Oct 5, 2026
When calling
Resolver::lookup()orResolver::lookup_ip()on a resolver with DNSSEC validation enabled, both methods returnOk(...)if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.References