DNS Server Vulnerability in CoreDNS by CoreDNS
CVE-2026-62994
3.7LOW
What is CVE-2026-62994?
A vulnerability exists in CoreDNS, affecting versions 1.9.4 through 1.14.5, where a network DNS client is able to request AXFR for a zone configured with headless service zone transfers. This configuration can lead to a panic situation when Kubernetes includes a headless service endpoint without declared ports. The handling of such conditions in the code can result in improper indexing and batch processing, leading to instability in server operations. This issue has been resolved in CoreDNS version 1.14.5.
Affected Version(s)
coredns >= 1.9.4, < 1.14.5
