CVE-2024-0874Medium· 5.3▾ SunlitA flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82399High· 7.5CoreDNS is a DNS server written in Go
CVE-2026-86003High· 7.5CoreDNS is a DNS server written in Go
CVE-2026-89639Medium· 5.5kernel: cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC (CVE-2026-89639)
CVE-2026-13697High· 7.4undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives (CVE-2026-13697)
CVE-2026-64648High· 7.5next: Next.js: Information disclosure via server-side fetch cache (CVE-2026-64648)
CVE-2026-26018High· 7.5CoreDNS is a DNS server that chains plugins