๐Ÿ” CVE Alert

CVE-2026-86003

HIGH 7.5

CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack without the dns.DefaultMsgAcceptFunc request policy used by UDP, TCP, and DNS-over-TLS. An unauthenticated client can send an RFC 2136 UPDATE that the proxy or forward plugin passes unchanged to an update-capable upstream. If that upstream trusts CoreDNS's source address or connection and does not require an attacker-unknown end-to-end TSIG, the request appears to originate from CoreDNS and can add, replace, or delete DNS records, redirect traffic, take over names, alter mail routing, or disrupt the writable zone. This issue is fixed in version 1.14.7.

CWE CWE-441
Vendor coredns
Product coredns
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for coredns coredns

Be the first to know when new high vulnerabilities affecting coredns coredns are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

coredns / coredns
< 1.14.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/coredns/coredns/security/advisories/GHSA-9gm5-9rfh-m6vx github.com: https://github.com/coredns/coredns/commit/530b0a5ff2ad68cc0421f10dd93568945cc671c9 github.com: https://github.com/coredns/coredns/releases/tag/v1.14.7