ZeroHour

CVE-2026-26018

PoC
CVSS 3.1
7.5 high
EPSS
1%p64
Published
()
Modified
Description

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.

Vendors
coredns.io
Products
coredns
Weakness
CWE-337, CWE-400, CWE-770, CWE-1241
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.