{"id":"CVE-2026-42254","aliases":["GHSA-83hf-93m4-rgwq"],"url":"https://o3.security/vulnerability/CVE-2026-42254","summary":"Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation","details":"Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.","published":"2026-04-26T02:38:41.261Z","modified":"2026-08-12T03:51:11.290084030Z","cvss":{"score":4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"},"epss":{"score":0.00162,"percentile":0.05944,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"hickory-recursor","fixedVersion":"0.26.0"},{"ecosystem":"crates.io","name":"hickory-recursor","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42254.json"},{"type":"ADVISORY","url":"https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-83hf-93m4-rgwq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42254"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:11.290084030Z"}}