Impact
Based on the description, it is inferred that CoreDNS does not apply the default message‑acceptance policy when unpacking DNS messages received over its DoH, DoQ, DoG, or DoQ listeners. This omission lets an unauthenticated client send an RFC 2136 UPDATE packet that the server forwards unchanged to an upstream DNS server that trusts its source address. As a result, an attacker can add, replace, or delete zone records, redirect traffic, hijack services, or disrupt mail routing.
Affected Systems
The vulnerability affects all CoreDNS releases prior to version 1.14.7 that enable any of the DNS‑over‑HTTPS, DNS‑over‑HTTP/3, DNS‑over‑QUIC, or DNS‑over‑gRPC listeners. The problematic code resides in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go. If an environment uses CoreDNS 1.14.6 or earlier with one of these listeners exposed, it is susceptible.
Risk and Exploitability
Based on the description, it is inferred that the exploitation path requires no special privileges on the CoreDNS server; an external attacker only needs network reach to the relevant secure‑transport ports. The assigned CVSS score of 7.5 reflects a high impact on confidentiality and integrity for zone data. However, the EPSS score of less than 1 % indicates a low current risk of exploitation, and the vulnerability is not listed in CISA KEV. Nonetheless, if an upstream server accepts UPDATEs from the CoreDNS address without TSIG validation, the attacker can gain full control over zone records.
OpenCVE Enrichment
Github GHSA