PT-2026-93904 · Coredns · Coredns

CVE-2026-86003

·

Published

2026-07-16

·

Updated

2026-09-28

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions CoreDNS versions prior to 1.14.7
Description CoreDNS fails to apply the dns.DefaultMsgAcceptFunc request policy when processing requests via DNS-over-HTTPS (DoH), DNS-over-HTTP/3 (DoH3), DNS-over-QUIC (DoQ), and DNS-over-gRPC listeners. Specifically, the dns.Msg.Unpack() function is called without the necessary policy checks in plugin/pkg/doh/doh.go, core/dnsserver/server quic.go, and core/dnsserver/server grpc.go.
This allows an unauthenticated client to send RFC 2136 UPDATE messages that the proxy or forward plugins pass unchanged to an upstream DNS server. If the upstream server trusts the source address of CoreDNS or the connection and does not require a Transaction Signature (TSIG), the request appears to originate from CoreDNS. An attacker can exploit this to add, replace, or delete DNS records, redirect traffic, take over domain names, alter mail routing, or disrupt writable zones.
Recommendations Update CoreDNS to version 1.14.7 or later. As a temporary mitigation, restrict access to the DoH, DoH3, DoQ, and DNS-over-gRPC listeners to trusted sources only. Ensure that upstream DNS servers require and validate end-to-end TSIG for all UPDATE requests.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-101835
BDU:2026-14833
CVE-2026-86003
ECHO-5DD9-46B5-527A
GHSA-9GM5-9RFH-M6VX
GO-2026-6506

Affected Products

Coredns