PT-2026-93904 · Coredns · Coredns
CVE-2026-86003
·
Published
2026-07-16
·
Updated
2026-09-28
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
CoreDNS versions prior to 1.14.7
Description
CoreDNS fails to apply the
dns.DefaultMsgAcceptFunc request policy when processing requests via DNS-over-HTTPS (DoH), DNS-over-HTTP/3 (DoH3), DNS-over-QUIC (DoQ), and DNS-over-gRPC listeners. Specifically, the dns.Msg.Unpack() function is called without the necessary policy checks in plugin/pkg/doh/doh.go, core/dnsserver/server quic.go, and core/dnsserver/server grpc.go.This allows an unauthenticated client to send RFC 2136 UPDATE messages that the
proxy or forward plugins pass unchanged to an upstream DNS server. If the upstream server trusts the source address of CoreDNS or the connection and does not require a Transaction Signature (TSIG), the request appears to originate from CoreDNS. An attacker can exploit this to add, replace, or delete DNS records, redirect traffic, take over domain names, alter mail routing, or disrupt writable zones.Recommendations
Update CoreDNS to version 1.14.7 or later.
As a temporary mitigation, restrict access to the DoH, DoH3, DoQ, and DNS-over-gRPC listeners to trusted sources only.
Ensure that upstream DNS servers require and validate end-to-end TSIG for all UPDATE requests.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coredns