CVE-2026-62299
- EPSS 0.31%
- Veröffentlicht 16.07.2026 19:44:36
- Zuletzt bearbeitet 22.07.2026 20:18:57
CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetResponseRule and edns0ReplaceResponseRule[T] in plugin/rewrite/edns0.go, cal...
CVE-2026-62309
- EPSS 0.38%
- Veröffentlicht 16.07.2026 19:42:17
- Zuletzt bearbeitet 22.07.2026 20:17:31
CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header with n...
CVE-2026-62994
- EPSS 0.3%
- Veröffentlicht 16.07.2026 19:39:05
- Zuletzt bearbeitet 22.07.2026 20:14:36
CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with k8s_external headless-service zone transfers and Kubernetes contains a...
CVE-2026-35579
- EPSS 0.51%
- Veröffentlicht 05.05.2026 21:16:22
- Zuletzt bearbeitet 24.07.2026 21:10:00
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the TSIG key name exists in the configura...
CVE-2026-32936
- EPSS 0.67%
- Veröffentlicht 05.05.2026 20:16:36
- Zuletzt bearbeitet 25.07.2026 11:10:00
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the ...
CVE-2026-33190
- EPSS 0.37%
- Veröffentlicht 05.05.2026 20:16:36
- Zuletzt bearbeitet 24.07.2026 23:10:00
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it trusts the transport writer's TsigStatus() instead of performing verifica...
CVE-2026-33489
- EPSS 0.39%
- Veröffentlicht 05.05.2026 20:16:36
- Zuletzt bearbeitet 24.07.2026 23:10:00
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer....
CVE-2026-32934
- EPSS 0.47%
- Veröffentlicht 05.05.2026 20:16:35
- Zuletzt bearbeitet 25.07.2026 11:10:00
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QUIC streams and sends only 1 byte per stream. When t...
CVE-2026-26017
- EPSS 0.39%
- Veröffentlicht 06.03.2026 15:36:15
- Zuletzt bearbeitet 15.07.2026 02:18:59
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the re...
CVE-2026-26018
- EPSS 1.12%
- Veröffentlicht 06.03.2026 15:35:50
- Zuletzt bearbeitet 15.07.2026 02:18:59
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerabil...