logo

CoreDNS Security Alert: Multiple High-Severity Vulnerabilities Patched in Version 1.14.3

ID: 8c3b86fb-4df2-5093-86ad-57b00d89e983

STIX ID: report--8c3b86fb-4df2-5093-86ad-57b00d89e983

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Ddos

...
...

CoreDNS released a security update (1.14.3) addressing five CVEs (all CVSS 7.5) affecting modern encrypted DNS transports (DoH, DoQ, gRPC). Reported issues include oversized DoH query handling leading to memory/CPU amplification and DoS, TSIG authentication bypass allowing unauthorized AXFR/IXFR transfers, unbounded QUIC stream handling causing OOM, and a subzone ACL selection bug exposing zone data; administrators are urged to patch or apply network-level mitigations until updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.