CoreDNS是CoreDNS社区的一个 DNS 服务器。 CoreDNS 1.14.3之前版本存在安全漏洞,该漏洞源于DNS-over-QUIC服务器中远程客户端打开大量QUIC流并仅发送1字节,可能导致无限制的goroutine和内存增长。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32936 | CoreDNS DoH GET path missing size validation causes CPU and memory amplification | |
| CVE-2026-33489 | CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison | |
| CVE-2026-33190 | CoreDNS TSIG authentication bypass on encrypted DNS transports | |
| CVE-2026-35579 | CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports |
No comments yet