5.3
CVE-2026-62299
- EPSS 0.31%
- Veröffentlicht 16.07.2026 19:44:36
- Zuletzt bearbeitet 22.07.2026 20:18:57
- CVE-Watchlists
- Unerledigt
CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record
CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetResponseRule and edns0ReplaceResponseRule[T] in plugin/rewrite/edns0.go, call res.IsEdns0() and immediately dereference the returned *dns.OPT without a nil check when a downstream plugin returns a response with no OPT record. A remote, unauthenticated client can send a single ordinary DNS query matching a rewrite edns0 <local|nsid|subnet> <set|append|replace> ... revert rule, causing ResponseReverter in plugin/rewrite/reverter.go to panic, return SERVFAIL, and degrade availability, or crash the CoreDNS process if the debug directive disables recovery. This issue is fixed in version 1.14.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Coredns.Io ≫ Coredns Version < 1.14.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.234 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://github.com/coredns/coredns/releases/tag/v1.14.5
https://github.com/coredns/coredns/security/advisories/GHSA-9pmm-cxww-rrr7
https://github.com/coredns/coredns/pull/8190
https://github.com/coredns/coredns/commit/fc447d0658b093edc8cd29a6b171216a44a644c2