Description
CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack without the dns.DefaultMsgAcceptFunc request policy used by UDP, TCP, and DNS-over-TLS. An unauthenticated client can send an RFC 2136 UPDATE that the proxy or forward plugin passes unchanged to an update-capable upstream. If that upstream trusts CoreDNS's source address or connection and does not require an attacker-unknown end-to-end TSIG, the request appears to originate from CoreDNS and can add, replace, or delete DNS records, redirect traffic, take over names, alter mail routing, or disrupt the writable zone. This issue is fixed in version 1.14.7.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized DNS updates
Action: Immediate Patch
AI Analysis

Impact

Based on the description, it is inferred that CoreDNS does not apply the default message‑acceptance policy when unpacking DNS messages received over its DoH, DoQ, DoG, or DoQ listeners. This omission lets an unauthenticated client send an RFC 2136 UPDATE packet that the server forwards unchanged to an upstream DNS server that trusts its source address. As a result, an attacker can add, replace, or delete zone records, redirect traffic, hijack services, or disrupt mail routing.

Affected Systems

The vulnerability affects all CoreDNS releases prior to version 1.14.7 that enable any of the DNS‑over‑HTTPS, DNS‑over‑HTTP/3, DNS‑over‑QUIC, or DNS‑over‑gRPC listeners. The problematic code resides in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go. If an environment uses CoreDNS 1.14.6 or earlier with one of these listeners exposed, it is susceptible.

Risk and Exploitability

Based on the description, it is inferred that the exploitation path requires no special privileges on the CoreDNS server; an external attacker only needs network reach to the relevant secure‑transport ports. The assigned CVSS score of 7.5 reflects a high impact on confidentiality and integrity for zone data. However, the EPSS score of less than 1 % indicates a low current risk of exploitation, and the vulnerability is not listed in CISA KEV. Nonetheless, if an upstream server accepts UPDATEs from the CoreDNS address without TSIG validation, the attacker can gain full control over zone records.

Generated by OpenCVE AI on September 18, 2026 at 02:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CoreDNS to version 1.14.7 or later.
  • Disable or restrict the use of DoH, DoQ, DNS‑over‑gRPC, and DNS‑over‑QUIC listeners if they are not needed for your environment.
  • Configure upstream DNS servers to require TSIG authentication for UPDATE requests and reject updates that originate from untrusted addresses.

Generated by OpenCVE AI on September 18, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9gm5-9rfh-m6vx CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Coredns.io
Coredns.io coredns
Vendors & Products Coredns.io
Coredns.io coredns

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack without the dns.DefaultMsgAcceptFunc request policy used by UDP, TCP, and DNS-over-TLS. An unauthenticated client can send an RFC 2136 UPDATE that the proxy or forward plugin passes unchanged to an update-capable upstream. If that upstream trusts CoreDNS's source address or connection and does not require an attacker-unknown end-to-end TSIG, the request appears to originate from CoreDNS and can add, replace, or delete DNS records, redirect traffic, take over names, alter mail routing, or disrupt the writable zone. This issue is fixed in version 1.14.7.
Title CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
Weaknesses CWE-441
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Coredns.io Coredns
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:25:42.634Z

Reserved: 2026-09-04T19:17:36.246Z

Link: CVE-2026-86003

cve-icon Vulnrichment

Updated: 2026-09-17T17:06:23.818Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:51.760

Modified: 2026-09-24T21:24:11.250

Link: CVE-2026-86003

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T18:39:22Z

Links: CVE-2026-86003 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:22Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')