CoreDNS是CoreDNS团队开源的一个 DNS 服务器。 CoreDNS 1.14.4之前版本存在异常处理不当漏洞,该漏洞源于 proxyproto 插件对 PROXY v2 头部非 UDP 传输的处理不当,导致解析错误后从空结果重新分配地址,并在 ServeDNS 恢复前调用 addr.String() 在警告日志中,从而可能使单个 28 字节 UDP 数据包崩溃 CoreDNS 进程,造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-62299 | 5.3 MEDIUM | CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downst |
| CVE-2026-62994 | 3.7 LOW | CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `tra |
No comments yet