Skip to content

chore(deps): bump hickory-resolver from 0.26.0 to 0.26.3 in the cargo-security group across 1 directory - #26556

Merged
thomasqueirozb merged 4 commits into
masterfrom
dependabot/cargo/cargo-security-3fb52d17f6
Oct 7, 2026
Merged

thomasqueirozb merged 4 commits into
masterfrom
dependabot/cargo/cargo-security-3fb52d17f6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the cargo-security group with 1 update in the / directory: hickory-resolver.

Updates hickory-resolver from 0.26.0 to 0.26.3

Release notes

Sourced from hickory-resolver's releases.

v0.26.3

This release fixes regressions introduced in v0.26.2 related to DNSSEC verification, QUIC servers, HTTP/3 servers, and minimum dependency versions.

What's Changed

Full Changelog: hickory-dns/hickory-dns@v0.26.2...v0.26.3

v0.26.2

This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in parsers. Other issues were related to UDP spoofing defenses, caching issues, and general DNS protocol correctness issues.

This is our first post-vulnpocalypse release, and most of these vulnerabilities were discovered through LLM-based workflows. The sheer volume of reports has been a challenge for our volunteer maintainers.

Resolved advisories:

  • GHSA-2vgh-3wfw-qj7c: RRSIG Signer's Name not checked against the RRset's zone
  • GHSA-57pw-897j-v4j6: Improper check of signature validity of NSEC and NSEC3 records
  • GHSA-wjgj-fvg9-65w9: DNSSEC validation ignores bogus records with a DNS class other than IN
  • GHSA-588m-chg6-8jqj: Inverted NSEC3 comparison allows forgery of proofs of nonexistence
  • GHSA-qw83-5pm2-ggp5: DNSSEC nonexistence forgery via incorrect handling of wraparound NSEC records
  • GHSA-3jvh-8vj5-65rq: NSEC3 apex NODATA accepted as secure with no QNAME-matching NSEC3
  • GHSA-3r6v-f3jh-vvqm: ancestor-delegation NSEC accepted as proof of nonexistence below the zone cut
  • GHSA-624w-vvww-xvpw: ancestor-delegation NSEC3 accepted as proof of nonexistence at and below the zone cut
  • GHSA-7php-9j59-g3ch: DNSSEC validation is missing RFC 6840 §4.4 checks
  • GHSA-vrv5-968r-5ggm: DNSSEC validation accepts bogus positive response with wildcard expansion
  • GHSA-p2jv-r3m3-7wf4: Nonexistence proof forgery due to insufficient checks on NSEC3 record names
  • GHSA-86vr-jm6c-7cpg: NSEC validator accepts NXDOMAIN for an empty non-terminal (ENT) that the covering NSEC proves exists
  • GHSA-8hq4-5836-w6q4: Server does not check validation status of SOA record in negative responses
  • GHSA-5j98-2g5x-46v6: Resolver::lookup() and Resolver::lookup_ip() APIs obscure DNSSEC validation failures
  • GHSA-929p-gjf6-5hqj: DNSSEC validation accepts responses with the wrong RRset as a positive answer
  • GHSA-j2rc-wxwh-62g9: TrustAnchors does not check name of DNSKEY
  • GHSA-rx82-4p2j-j5cv: Name::hash discards label boundaries; ValidationCacheKey(u64) reuses the digest in Eq implementation, leaking an Insecure DNSSEC verdict across distinct owner names
  • GHSA-2hxp-x833-73f7: Hickory DNS recursor: ghost domain attack via child-side NS RRset queries
  • GHSA-x962-5xwx-fr8x: Unchecked subtraction in TSIG RDATA decoding panics when overflow checks are enabled
  • GHSA-wgfr-mphw-j5g4: Panic in zone file parser for SVCB and HTTPS
  • GHSA-hx8c-fjhc-hmf5: Panic in zone file parser for SVCB and HTTPS
  • GHSA-4rph-pmrw-mwpw: Zone file parser panics when parsing long lines
  • GHSA-3w89-7rx5-hpwx: Responses with QDCOUNT=0 bypass check for matching question section
  • GHSA-vcjp-57rr-mpfw: Out-of-bailiwick filtering is not applied to negative responses
  • GHSA-6w6g-hm98-mhgm: Unbounded TC-retry loop in NameServerPool::try_send (resource-exhaustion DoS)
  • GHSA-cx5j-p54p-q756: Cyclic sibling domain name server referrals without glue records cause exponential upstream query amplification in the recursor
  • GHSA-6h5c-jjg5-wj59: Glueless-NS referral fan-out without per-query work budget
  • GHSA-v44v-c8m4-gc43: Denial of service of client UDP connections via spoofed malformed responses
  • GHSA-67wc-6jq8-ghrc: Remote memory-amplification DoS via attacker-controlled RR counts in DNS message parsing

... (truncated)

Commits
  • bd37caf net: require authenticated insecure-delegation proofs
  • 5a79511 Add conformance test for regression
  • c268442 net: fix ancestor delegation issues
  • 9488e8e Exclude accepting QUIC connections from timeouts
  • 4ad16c3 Bump version to 0.26.3
  • cfab556 proto: ignore RRSIGs in DnssecSummary::from_records
  • 819a6bc net: try every RRSIG before marking an RRset bogus
  • 688231e resolver: use lenient resolv.conf parsing
  • ca5d1a1 resolver: Fix 'unused method' with features blocklist,tls-ring
  • 678b01b Fix unnecessary qualification warning
  • Additional commits viewable in compare view

@dependabot
dependabot Bot requested a review from a team as a code owner October 6, 2026 13:50
@dependabot dependabot Bot added domain: deps Anything related to Vector's dependencies no-changelog Changes in this PR do not need user-facing explanations in the release changelog labels Oct 6, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T20:37:11.922542Z cabe36b New commits
🔒 Security Review ✅ Completed 2026-10-06T20:38:24.698324Z cabe36b New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@datadoghq-integration datadoghq-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: PASS

More details

Static review found no concrete compatibility defect in Vector’s resolver integration or the collateral lockfile changes accompanying Hickory 0.26.3. Runtime DNS behavior was not independently validated.

Was this helpful? React 👍 or 👎

Open Bits AI session

🤖 Bits Code Review · Commit 61d51a0 · @DataDog review to ask questions

Bumps the cargo-security group with 1 update in the / directory: [hickory-resolver](https://github.com/hickory-dns/hickory-dns).


Updates `hickory-resolver` from 0.26.0 to 0.26.3
- [Release notes](https://github.com/hickory-dns/hickory-dns/releases)
- [Changelog](https://github.com/hickory-dns/hickory-dns/blob/main/CHANGELOG.md)
- [Commits](hickory-dns/hickory-dns@v0.26.0...v0.26.3)

---
updated-dependencies:
- dependency-name: hickory-resolver
  dependency-version: 0.26.3
  dependency-type: indirect
  dependency-group: cargo-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/cargo/cargo-security-3fb52d17f6 branch from 61d51a0 to 82c9e36 Compare October 6, 2026 14:58
@thomasqueirozb
thomasqueirozb added this pull request to the merge queue Oct 7, 2026
Merged via the queue into master with commit 9dcd732 Oct 7, 2026
83 checks passed
@thomasqueirozb
thomasqueirozb deleted the dependabot/cargo/cargo-security-3fb52d17f6 branch October 7, 2026 14:11
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 7, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

domain: deps Anything related to Vector's dependencies no-changelog Changes in this PR do not need user-facing explanations in the release changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants