pkg:Go/github.com/coredns/coredns
24 total CVEsHIGH14MEDIUM6LOW2
✅ Check your installed version
All known vulnerabilities
- from 0, < 1.14.2
- from 0, < 1.14.2
- from 0, < 1.14.3
- from 0, < 1.14.3
- HIGH7.5CVE-2026-33489CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)from 0, < 1.14.3
- HIGH7.5CVE-2026-32936CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplificationfrom 0, < 1.14.3
- from 0, < 1.14.3
- from 0, < 1.14.3
- from 0, < 1.14.2
- from 0, < 1.14.2
- HIGH7.5CVE-2025-47950CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification in github.com/coredns/corednsfrom 0, < 1.12.2
- HIGH7.5CVE-2025-47950CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification in github.com/coredns/corednsfrom 0, < 1.12.2
- >= 1.2.0, < 1.12.4
- >= 1.2.0, < 1.12.4
- MEDIUM6.1CVE-2022-2837coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpointsfrom 0, <= 1.9.3
- from 0, < 1.11.0
- from 0, < 1.11.0
- from 0, < 1.11.2
- from 0, < 1.11.2
- MEDIUM4.4CVE-2022-2835coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpointsfrom 0, <= 1.9.3
- from 0, <= 1.10.1
- from 0, < 1.11.0
- —CVE-2025-68151CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messagesfrom 0, < 1.14.0
- —CVE-2025-68151CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messagesfrom 0, < 1.14.0