CoreDNS Security Alert: Multiple High-Severity Vulnerabilities Patched in Version 1.14.3
ID: 8c3b86fb-4df2-5093-86ad-57b00d89e983
STIX ID: report--8c3b86fb-4df2-5093-86ad-57b00d89e983
Feed Name: securityonline.info
CoreDNS released a security update (1.14.3) addressing five CVEs (all CVSS 7.5) affecting modern encrypted DNS transports (DoH, DoQ, gRPC). Reported issues include oversized DoH query handling leading to memory/CPU amplification and DoS, TSIG authentication bypass allowing unauthorized AXFR/IXFR transfers, unbounded QUIC stream handling causing OOM, and a subzone ACL selection bug exposing zone data; administrators are urged to patch or apply network-level mitigations until updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
