NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2577 most downloaded on crates.io
hickory-net is a safe and secure low-level DNS library. This is the foundational DNS protocol library used by the other higher-level Hickory DNS crates.
Last release 27 days ago
10 Sep 2026
Release timing varies
gaps range from 2 weeks to 4 months
Nearly every release is documented
notes for 4 of 4 stable releases
Nothing withdrawn
no release was ever pulled
6 months old
8 releases · first in 2026
One column per month.
This release fixes regressions introduced in v0.26.2 related to DNSSEC verification, QUIC servers, HTTP/3 servers, and minimum dependency versions.
This release fixes regressions introduced in v0.26.2 related to DNSSEC verification, QUIC servers, HTTP/3 servers, and minimum dependency versions.
Full Changelog: v0.26.2...v0.26.3
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource co…
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in parsers. Other issues were related to UDP spoofing defenses, caching issues, and general DNS protocol correctness issues.
This is our first post-vulnpocalypse release, and most of these vulnerabilities were discovered through LLM-based workflows. The sheer volume of reports has been a challenge for our volunteer maintainers.
Resolved advisories:
TrustAnchors does not check name of DNSKEYName::hash discards label boundaries; ValidationCacheKey(u64) reuses the digest in Eq implementation, leaking an Insecure DNSSEC verdict across distinct owner namesNameServerPool::try_send (resource-exhaustion DoS)Special thanks go out to @qifan-sailboat and Palo Alto Networks for their research and for reporting the bulk of these vulnerabilities. Thanks to @ATinyShoe, @kirk-baird, @thesmartshadow, @BeaCox, @jpds, @N0zoM1z0, and @JasonPap for reporting vulnerabilities as well.
If your organization is interested in coordinated disclosure of future security vulnerabilities, please contact @djc for commercial support.
Full Changelog: v0.26.1...v0.26.2
This point release for the 0.26 release series brings in several bug fixes, and no user-facing changes. Two security reports are addressed: RUSTSEC-20
This point release for the 0.26 release series brings in several bug fixes, and no user-facing changes. Two security reports are addressed:
RUSTSEC-2026-0120 and RUSTSEC-2026-0119.
Full Changelog: v0.26.0...v0.26.1
13 months after the release of 0.25.0, we finally have a bigger feature release of Hickory DNS, the suite of DNS libraries and authoritative/recursive
13 months after the release of 0.25.0, we finally have a bigger feature release of Hickory DNS, the suite of DNS libraries and authoritative/recursive name servers written in pure Rust. A lot of work has gone into this release, so we wanted to take a moment to release this before we continue work on deploying the Hickory DNS recursive resolver at Let's Encrypt (and did you see that Hickory is being used in some of Google's Pixel devices?). Because of the ongoing work, we expect that 0.27.0 might happen quite a bit sooner than in 13 months from now.
These release notes describe a number of high-level improvements as well as API changes that are likely to break a larger fraction of our downstream users. Feedback (both on these notes and the release itself) is always welcome in our issue tracker or via our Discord server.
Most of the following notes are broken up by specific components: the server binary and our library crates. However, for this release we've made several changes to the structure of our crates itself:
client module (#3366). No future releases of the hickory-client crate are expected.recursor feature which must be enabled explicitly. The recursor implementation was already tightly coupled to the resolver internals, so keeping it separate didn't really make sense.Additionally, substantial cross-crate changes have been made to improve our error handling:
Authority trait was renamed to ZoneHandler and simplified to better reflect its usage:
We made many improvements to improve correctness and efficiency of both the recursive resolver and the "stub" resolver. In addition, we want to highlight the following changes:
We made substantial improvements to DNSSEC validation and our handling of potentially spoofing messages.
For more details, review the detailed release notes for our pre-releases:
and these final PRs merged after beta 4:
Finally, we want to thank everyone who contributed to this release: @bryanlarsen, @billf, @hargut, @ibigbug, @xi0, @steffengy, @james7132, @Thomasdezeeuw, @Kriskras99, @mispp, @conradludgate, @nabijaczleweli, @musicinmybrain, @msrd0, @jmwample, @LAGonauta, @tisonkun, @provokateurin, @lemon-sh, @thomas-zahner, @jpds, @lpraneis, @zachsmith1, @jackboykin, @ZnqbuZ, @Jeidnx, @kn0sys, @matheus23, @benesch, @roblabla and of course our maintainers @cpu, @divergentdave, @marcus0x62 and @djc.
bin: add SO_REUSEPORT support with configurable UDP socket count by @cpu in #3549
resolver: Fix positive_min_ttl not clamping stored record TTLs by @jpds in #3550
proto: default to enabling EDNS, increase max payload length by @djc in #3498
server: remove deprecated ZoneType enum variants by @cpu in #3061
preserve_rdata fuzzer improvements by @divergentdave in #3047RetryDnsHandle tweaks by @djc in #3185ResolverOpts tidying by @cpu in #3225Note truncated.
Your coding agent can read these notes before it upgrades. Set up the MCP server →