DNS Server Vulnerability in CoreDNS by CoreDNS
CVE-2026-62994

3.7LOW

Key Information:

Vendor

Coredns

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-62994?

A vulnerability exists in CoreDNS, affecting versions 1.9.4 through 1.14.5, where a network DNS client is able to request AXFR for a zone configured with headless service zone transfers. This configuration can lead to a panic situation when Kubernetes includes a headless service endpoint without declared ports. The handling of such conditions in the code can result in improper indexing and batch processing, leading to instability in server operations. This issue has been resolved in CoreDNS version 1.14.5.

Affected Version(s)

coredns >= 1.9.4, < 1.14.5

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.