HIGH🇵🇱 Wersja polska

CVE-2026-62309

CVSS 7.5v3.1pub. 2026-07-16upd. 2026-07-22

CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header with non-UDP transport such as family byte 0x11, reassigns addr from a nil readFrom result after parseProxyProtocol errors, and calls addr.String() in the warning log before ServeDNS recovery applies. This issue is fixed in version 1.14.4.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Coredns.io Coredns

    APP
    Coredns.Io
    < 1.14.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-33489HIGH8.2same product

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the w...

CVE-2026-32934HIGH8.7same product

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can b...

CVE-2026-32936HIGH8.7same product

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path ac...

CVE-2026-33190HIGH8.7same product

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on n...

CVE-2026-35579HIGH8.2same product

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport im...