NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #972 most downloaded on crates.io
hickory-resolver is a safe and secure DNS stub resolver library intended to be a high-level library for DNS record resolution.
Last release 28 days ago
10 Sep 2026
Ships unpredictably
gaps range from 2 weeks to 9 months
Some releases are documented
notes for 7 of 13 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
23 releases · first in 2023
This release fixes regressions introduced in v0.26.2 related to DNSSEC verification, QUIC servers, HTTP/3 servers, and minimum dependency versions.
This release fixes regressions introduced in v0.26.2 related to DNSSEC verification, QUIC servers, HTTP/3 servers, and minimum dependency versions.
Full Changelog: v0.26.2...v0.26.3
One column per quarter.
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource co…
This release fixes a large number of security vulnerabilities. Most of the issues were related to DNSSEC validation, denial of service and resource consumption attacks, and reachable panics in parsers. Other issues were related to UDP spoofing defenses, caching issues, and general DNS protocol correctness issues.
This is our first post-vulnpocalypse release, and most of these vulnerabilities were discovered through LLM-based workflows. The sheer volume of reports has been a challenge for our volunteer maintainers.
Resolved advisories:
TrustAnchors does not check name of DNSKEYName::hash discards label boundaries; ValidationCacheKey(u64) reuses the digest in Eq implementation, leaking an Insecure DNSSEC verdict across distinct owner namesNameServerPool::try_send (resource-exhaustion DoS)Special thanks go out to @qifan-sailboat and Palo Alto Networks for their research and for reporting the bulk of these vulnerabilities. Thanks to @ATinyShoe, @kirk-baird, @thesmartshadow, @BeaCox, @jpds, @N0zoM1z0, and @JasonPap for reporting vulnerabilities as well.
If your organization is interested in coordinated disclosure of future security vulnerabilities, please contact @djc for commercial support.
Full Changelog: v0.26.1...v0.26.2
This point release for the 0.26 release series brings in several bug fixes, and no user-facing changes. Two security reports are addressed: RUSTSEC-20
This point release for the 0.26 release series brings in several bug fixes, and no user-facing changes. Two security reports are addressed:
RUSTSEC-2026-0120 and RUSTSEC-2026-0119.
Full Changelog: v0.26.0...v0.26.1
13 months after the release of 0.25.0, we finally have a bigger feature release of Hickory DNS, the suite of DNS libraries and authoritative/recursive
13 months after the release of 0.25.0, we finally have a bigger feature release of Hickory DNS, the suite of DNS libraries and authoritative/recursive name servers written in pure Rust. A lot of work has gone into this release, so we wanted to take a moment to release this before we continue work on deploying the Hickory DNS recursive resolver at Let's Encrypt (and did you see that Hickory is being used in some of Google's Pixel devices?). Because of the ongoing work, we expect that 0.27.0 might happen quite a bit sooner than in 13 months from now.
These release notes describe a number of high-level improvements as well as API changes that are likely to break a larger fraction of our downstream users. Feedback (both on these notes and the release itself) is always welcome in our issue tracker or via our Discord server.
Most of the following notes are broken up by specific components: the server binary and our library crates. However, for this release we've made several changes to the structure of our crates itself:
client module (#3366). No future releases of the hickory-client crate are expected.recursor feature which must be enabled explicitly. The recursor implementation was already tightly coupled to the resolver internals, so keeping it separate didn't really make sense.Additionally, substantial cross-crate changes have been made to improve our error handling:
Authority trait was renamed to ZoneHandler and simplified to better reflect its usage:
We made many improvements to improve correctness and efficiency of both the recursive resolver and the "stub" resolver. In addition, we want to highlight the following changes:
We made substantial improvements to DNSSEC validation and our handling of potentially spoofing messages.
For more details, review the detailed release notes for our pre-releases:
and these final PRs merged after beta 4:
Finally, we want to thank everyone who contributed to this release: @bryanlarsen, @billf, @hargut, @ibigbug, @xi0, @steffengy, @james7132, @Thomasdezeeuw, @Kriskras99, @mispp, @conradludgate, @nabijaczleweli, @musicinmybrain, @msrd0, @jmwample, @LAGonauta, @tisonkun, @provokateurin, @lemon-sh, @thomas-zahner, @jpds, @lpraneis, @zachsmith1, @jackboykin, @ZnqbuZ, @Jeidnx, @kn0sys, @matheus23, @benesch, @roblabla and of course our maintainers @cpu, @divergentdave, @marcus0x62 and @djc.
bin: add SO_REUSEPORT support with configurable UDP socket count by @cpu in #3549
resolver: Fix positive_min_ttl not clamping stored record TTLs by @jpds in #3550
proto: default to enabling EDNS, increase max payload length by @djc in #3498
server: remove deprecated ZoneType enum variants by @cpu in #3061
preserve_rdata fuzzer improvements by @divergentdave in #3047RetryDnsHandle tweaks by @djc in #3185ResolverOpts tidying by @cpu in #3225Note truncated.
Inline all format argument, split out NoRecords type by @djc in #2966
large_enum_variants warnings by @djc in #3001Rewrite Dockerfile with cargo-chef by @divergentdave in #2874
ns_pool_for_zone() by @divergentdave in #2888ResolverBuilder::with_options() method by @cratelyn in #2877tshark output by @divergentdave in #2868TBS::new() by @divergentdave in #2942This is a small patch release to address errors that prevented publication of version 0.25.0 of some crates.
This is a small patch release to address errors that prevented publication of version 0.25.0 of some crates.
Full Changelog: v0.25.0...v0.25.1
Your coding agent can read these notes before it upgrades. Set up the MCP server →