coredns has 5 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.5 (high). None have a confirmed exploitation report. Most affected products: github.com/coredns/coredns (3), coredns (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 2 prev 2
Weakness classes
Products
- github.com/coredns/coredns 3
- coredns 2
Worst active — by depth score
CVE-2026-82399High· 7.5CoreDNS is a DNS server written in Go53CVE-2026-86003High· 7.5CoreDNS is a DNS server written in Go41CVE-2026-32936High· 7.5CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification41CVE-2026-32934High· 7.5CoreDNS' DoQ worker pool does not bound stream backlog41CVE-2025-68151MediumCoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages28
coredns vulnerabilities
CVEs affecting coredns, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-82399High· 7.5PoCCoreDNS is a DNS server written in Go
CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call d…
CVE-2026-86003High· 7.5CoreDNS is a DNS server written in Go
CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.M…
CVE-2026-32936High· 7.5CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CVE-2026-32934High· 7.5CoreDNS' DoQ worker pool does not bound stream backlog
CoreDNS' DoQ worker pool does not bound stream backlog
CVE-2025-68151MediumCoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages