Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

coreDNS — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in coreDNS, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive vulnerability aggregation view for coreDNS, specifically focusing on common weakness enumeration tags associated with the DNS resolution infrastructure. It compiles security issues ranging from buffer overflows and race conditions to configuration errors and protocol specification deviations that affect the stability and integrity of the service. The collected data covers vulnerabilities disclosed between 2018 and early 2024, capturing the evolution of threat landscapes as the product matured and expanded its feature set. Users can utilize this resource to systematically track advisories issued by the coreDNS maintainers and related security vendors, ensuring they are aware of critical updates and patch availability. The page also serves as an analytical tool for understanding the prevalence and impact of specific weakness classes within the coreDNS ecosystem, helping security professionals identify recurring patterns in code quality or design flaws. Additionally, administrators can look up the complete vulnerability history of the product to assess historical exposure, evaluate remediation timelines, and inform risk management decisions for environments relying on this DNS proxy and forwarder. This structured approach facilitates better security posture management by providing clear, aggregated insights without requiring manual searching across multiple disparate sources.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record CWE-476 5.3 Medium 2026-07-16
CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS CWE-476 7.5 High 2026-07-16
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin CWE-248 3.7 Low 2026-07-16
CVE-2026-35579 CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports CWE-287 7.4 - 2026-05-05
CVE-2026-33489 CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison CWE-863 7.5 - 2026-05-05
CVE-2026-32936 CoreDNS DoH GET path missing size validation causes CPU and memory amplification CWE-400 7.5 - 2026-05-05
CVE-2026-32934 CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service CWE-770 7.5 - 2026-05-05
CVE-2026-33190 CoreDNS TSIG authentication bypass on encrypted DNS transports CWE-303 7.4 - 2026-05-05
CVE-2026-26017 CoreDNS ACL Bypass CWE-367 7.7 High 2026-03-06
CVE-2026-26018 CoreDNS Loop Detection Denial of Service Vulnerability CWE-337 7.5 High 2026-03-06
CVE-2025-68151 CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages CWE-770 7.5 - 2026-01-08
CVE-2025-58063 CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion CWE-681 7.1 High 2025-09-09
CVE-2025-47950 CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification CWE-770 7.5 High 2025-06-06
CVE-2022-2835 CoreDNS 安全漏洞 CWE-923 4.4 - 2023-03-03
CVE-2022-2837 CoreDNS 输入验证错误漏洞 CWE-923 6.1 - 2023-03-03

All 15 known CVE vulnerabilities affecting coreDNS with full Chinese analysis, references, and POCs where available.