Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2026-42254

CVE-2026-42254

Medium
Open
TLP:CLEAR
NVD CVE.org
Critical Infrastructure

AI Analysis

· 2 months ago

Executive Summary

The Hickory DNS hickory-recursor vulnerability has a medium severity rating and a low CVSS score, indicating a relatively low likelihood of exploitation. However, the vulnerability can still be exploited to compromise DNS resolution, leading to malicious activities. The business impact of this vulnerability is moderate, as it can affect the integrity of DNS resolution and potentially lead to security breaches.

Enhanced Description

The Hickory DNS hickory-recursor versions 0.1 through 0.25.2 are vulnerable to cross-zone poisoning due to a flaw in cache management. Specifically, the cached data is not directly associated with the query that triggered the response, allowing an attacker to inject malicious data into the cache. This can lead to compromised DNS resolution, where an attacker can redirect users to malicious websites or intercept sensitive information. The attack vector for this vulnerability involves an attacker sending a carefully crafted query to the vulnerable DNS server, which then caches the malicious response. The potential impact of this vulnerability is significant, as it can compromise the integrity of DNS resolution, leading to a range of malicious activities such as phishing, malware distribution, and data theft.

Exploitation Context

An attacker can exploit this vulnerability by sending a carefully crafted query to the vulnerable DNS server, which then caches the malicious response. The attacker's motivation to exploit this vulnerability is to compromise the integrity of DNS resolution, potentially leading to phishing, malware distribution, or data theft.

Patch Priority

Medium
The vulnerability has a medium severity rating and a relatively low CVSS score, but it is still essential to prioritize remediation to prevent potential future attacks.

Recommended Actions

  • Update Hickory DNS hickory-recursor to a version later than 0.25.2
  • Implement DNS query validation and caching mechanisms to prevent cross-zone poisoning
  • Monitor DNS traffic for suspicious activity and implement incident response plans

Suggested Tags

cross-zone-poisoning
DNS-vulnerability
cache-poisoning

Confidence Assessment

The confidence in the severity ratings and exploitation likelihood is moderate, as the CVSS score and EPSS score suggest a relatively low likelihood of exploitation, but the potential impact of the vulnerability is still significant.

Description

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

Details

CVSS Score
4.0
EPSS Score
0.16%

5.9th percentile

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Confidence
90%
Published
Apr 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.