Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

coredns — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting coredns. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CoreDNS serves as a flexible DNS server and proxy, widely used in Kubernetes environments for service discovery and DNS resolution. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and insecure default configurations. While no major public incidents have been widely documented, the 10 recorded CVEs highlight potential risks in plugin handling and memory management. Security characteristics include a modular plugin architecture that can introduce attack surfaces, though regular updates and proper configuration mitigate many threats. The project maintains a responsive security team, but administrators should remain vigilant about plugin dependencies and access controls to prevent exploitation.

Found 13 results / 13 Clear Filters
Top products by coredns: coredns
CVE ID Title CVSS Severity Published
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record — coredns CWE-476 5.3 Medium 2026-07-16
CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS — coredns CWE-476 7.5 High 2026-07-16
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin — coredns CWE-248 3.7 Low 2026-07-16
CVE-2026-35579 CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports — coredns CWE-287 7.4 - 2026-05-05
CVE-2026-33489 CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison — coredns CWE-863 7.5 - 2026-05-05
CVE-2026-32936 CoreDNS DoH GET path missing size validation causes CPU and memory amplification — coredns CWE-400 7.5 - 2026-05-05
CVE-2026-32934 CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service — coredns CWE-770 7.5 - 2026-05-05
CVE-2026-33190 CoreDNS TSIG authentication bypass on encrypted DNS transports — coredns CWE-303 7.4 - 2026-05-05
CVE-2026-26017 CoreDNS ACL Bypass — coredns CWE-367 7.7 High 2026-03-06
CVE-2026-26018 CoreDNS Loop Detection Denial of Service Vulnerability — coredns CWE-337 7.5 High 2026-03-06
CVE-2025-68151 CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages — coredns CWE-770 7.5 - 2026-01-08
CVE-2025-58063 CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion — coredns CWE-681 7.1 High 2025-09-09
CVE-2025-47950 CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification — coredns CWE-770 7.5 High 2025-06-06

This page lists every published CVE security advisory associated with coredns. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.