CoreDNS is a prominent DNS server implementation widely deployed in Kubernetes clusters and containerized environments as the default in-cluster DNS resolver. Vulnerabilities in this product recur around resource-exhaustion and authentication-related weaknesses—including uncontrolled resource consumption, authentication bypass, and improper channel restriction—that reflect the protocol-parsing and access-control demands of a DNS service exposed to untrusted network inputs. Defenders should prioritize CoreDNS updates in Kubernetes infrastructure, as flaws in the cluster DNS layer can affect workload communication and service discovery; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coredns.Io over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35579CRITICAL CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUI | May 5, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-62309HIGH CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxypr | Jul 16, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-33190HIGH CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it tru | May 5, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-33489HIGH CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone ar | May 5, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-32936HIGH CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query par | May 5, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-32934HIGH CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client | May 5, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-62299MEDIUM CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetRespon | Jul 16, 2026 | 5.3 | 29 | NO | NO |
CVE-2026-26018HIGH CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash t | Mar 6, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-26017MEDIUM CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution orde | Mar 6, 2026 | 6.3 | 27 | NO | NO |
CVE-2025-68151HIGH CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical resource-limiting controls. An | Jan 8, 2026 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coredns.Io.
Media articles that mention a CVE ID that affects a product developed by Coredns.Io — matched by CVE ID, not by vendor name.