Skip to main content

Vendor/product archive

coredns.io / coredns CVEs

Beta · best-effort

16 CVEs tagged to coredns.io / coredns0 Critical, 11 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-62994

Published Jul 16, 2026

CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with…

CVSS 3.7 · Low
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-62309

Published Jul 16, 2026

CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyp…

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-62299

Published Jul 16, 2026

CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetRespo…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-35579

Published May 5, 2026

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QU…

CVSS 8.2 · High
evidence mentions
6
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2026-33489

Published May 5, 2026

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone a…

CVSS 8.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-33190

Published May 5, 2026

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it tr…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-32936

Published May 5, 2026

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query pa…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-32934

Published May 5, 2026

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote clien…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-26018

Published Mar 6, 2026

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash…

CVSS 7.5 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-26017

Published Mar 6, 2026

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution ord…

CVSS 7.7 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2025-68151

Published Jan 8, 2026

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical resource-limiting controls. A…

CVSS 6.6 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-47950

Published Jun 6, 2025

CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) server implementation.…

CVSS 7.5 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2023-30464

Published Sep 18, 2024

CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28452

Published Sep 18, 2024

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2837

Published Mar 3, 2023

A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and nam…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2835

Published Mar 3, 2023

A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of <service>.<namespa…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1