Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Coredns.Io

First CVE: Mar 3, 2023Active for: 3 yearsTotal CVEs: 16
43.4
VTI Score
High

CoreDNS is a prominent DNS server implementation widely deployed in Kubernetes clusters and containerized environments as the default in-cluster DNS resolver. Vulnerabilities in this product recur around resource-exhaustion and authentication-related weaknesses—including uncontrolled resource consumption, authentication bypass, and improper channel restriction—that reflect the protocol-parsing and access-control demands of a DNS service exposed to untrusted network inputs. Defenders should prioritize CoreDNS updates in Kubernetes infrastructure, as flaws in the cluster DNS layer can affect workload communication and service discovery; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Coredns.Io over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2023
3 years ago
Most Recent CVE
Jul 16, 2026
9 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-35579CRITICAL
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUI
May 5, 20269.839NONO
CVE-2026-62309HIGH
CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxypr
Jul 16, 20267.535NONO
CVE-2026-33190HIGH
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it tru
May 5, 20267.534NONO
CVE-2026-33489HIGH
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone ar
May 5, 20267.533NONO
CVE-2026-32936HIGH
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query par
May 5, 20267.530NONO
CVE-2026-32934HIGH
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client
May 5, 20267.530NONO
CVE-2026-62299MEDIUM
CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an optional revert flag, and two response rules, edns0SetRespon
Jul 16, 20265.329NONO
CVE-2026-26018HIGH
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash t
Mar 6, 20267.529NONO
CVE-2026-26017MEDIUM
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution orde
Mar 6, 20266.327NONO
CVE-2025-68151HIGH
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical resource-limiting controls. An
Jan 8, 20267.525NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
25%
63%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High2 (12.5%)
Unknown0 (0.0%)
User Interaction
None15 (93.8%)
Unknown0 (0.0%)
Required1 (6.3%)
Privileges Required
Low2 (12.5%)
High0 (0.0%)
None14 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Coredns.Io.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Coredns.Io — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Coredns.Io's Products

View all 3 CNAs →

Top CWEs