CoreDNS是CoreDNS团队开源的一个 DNS 服务器。 CoreDNS 1.9.4版本至1.14.5之前版本存在异常处理不当漏洞,该漏洞源于在配置k8s_external headless-service zone transfers且Kubernetes包含无声明端口的headless service endpoint时,未检查批次是否为空就索引记录,可能导致网络DNS客户端触发恐慌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-62309 | 7.5 HIGH | CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte |
| CVE-2026-62299 | 5.3 MEDIUM | CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downst |
No comments yet