Where
-Infinity
0

CoreDNS CoreDNSCoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record

Risk 27
Severity
5.3
First published (updated )

CoreDNS CoreDNSCoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS

Risk 43
Severity
7.5
First published (updated )

CoreDNS CoreDNSCoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin

Risk 20
Severity
3.7
First published (updated )

go/github.com/coredns/corednsCoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports

Risk 86
Severity
8.2
First published (updated )

go/github.com/coredns/corednsCoreDNS TSIG authentication bypass on encrypted DNS transports

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/github.com/coredns/corednsCoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison

Risk 43
Severity
8.2
First published (updated )

go/github.com/coredns/corednsCoreDNS DoH GET path missing size validation causes CPU and memory amplification

Risk 47
Severity
8.7
First published (updated )

go/github.com/coredns/corednsCoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service

Risk 47
Severity
8.7
First published (updated )

CoreDNS CoreDNSCoreDNS ACL Bypass

Risk 44
Severity
7.7
First published (updated )

CoreDNS CoreDNSCoreDNS Loop Detection Denial of Service Vulnerability

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

coredns/corednsCoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages

Risk 43
Severity
7.5
First published (updated )

CoreDNS CoreDNSCoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification

Risk 43
Severity
7.5
First published (updated )

go/github.com/coredns/corednsAn issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving softwar…

Risk 45
Severity
7.5
First published (updated )

go/github.com/coredns/corednsCoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses vi…

Risk 45
Severity
7.5
First published (updated )

coredns.io CoreDNSA flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for exte…

Risk 39
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

coredns.io CoreDNSA flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some int…

Risk 29
Severity
4.4
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203