Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

coreDNS — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in coreDNS, with AI-generated Chinese analysis, references, and POCs.

This is a vulnerability aggregation page for coreDNS, a widely used open-source DNS server, focusing on common weakness enumerations and security advisories. The page collects records of identified vulnerabilities affecting coreDNS, spanning from its initial public releases through recent updates to ensure comprehensive coverage of the product's security history. Here, security professionals and system administrators can track vendor advisories issued by the coreDNS project and its maintaining organizations to stay informed about critical patches. Users can also delve into specific weakness classes to understand the underlying causes of vulnerabilities, such as configuration errors, logic flaws, or dependency issues, which often impact DNS infrastructure. Additionally, this resource allows for a detailed look at a product's vulnerability history, providing context on how the software has evolved in response to security threats over time. By aggregating data from various sources, the page serves as a centralized reference for assessing the security posture of coreDNS deployments. It helps organizations prioritize remediation efforts by highlighting the severity and prevalence of known issues. The information presented is intended to support informed decision-making regarding updates, mitigations, and risk management strategies. This approach ensures that users have access to a structured overview of security events without the noise of unrelated data, facilitating more efficient security operations and compliance reporting for teams relying on coreDNS for their network infrastructure.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record CWE-476 5.3 Medium2026-07-16
CVE-2026-62309 CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS CWE-476 7.5 High2026-07-16
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin CWE-248 3.7 Low2026-07-16
CVE-2026-35579 CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports CWE-287 7.4 -2026-05-05
CVE-2026-33489 CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison CWE-863 7.5 -2026-05-05
CVE-2026-32936 CoreDNS DoH GET path missing size validation causes CPU and memory amplification CWE-400 7.5 -2026-05-05
CVE-2026-32934 CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service CWE-770 7.5 -2026-05-05
CVE-2026-33190 CoreDNS TSIG authentication bypass on encrypted DNS transports CWE-303 7.4 -2026-05-05
CVE-2026-26017 CoreDNS ACL Bypass CWE-367 7.7 High2026-03-06
CVE-2026-26018 CoreDNS Loop Detection Denial of Service Vulnerability CWE-337 7.5 High2026-03-06
CVE-2025-68151 CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages CWE-770 7.5 -2026-01-08
CVE-2025-58063 CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion CWE-681 7.1 High2025-09-09
CVE-2025-47950 CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification CWE-770 7.5 High2025-06-06
CVE-2022-2835 CoreDNS 安全漏洞 CWE-923 4.4 -2023-03-03
CVE-2022-2837 CoreDNS 输入验证错误漏洞 CWE-923 6.1 -2023-03-03

All 15 known CVE vulnerabilities affecting coreDNS with full Chinese analysis, references, and POCs where available.