Vulnerability GO-2026-5667
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
June 25, 2026 at 10:34 PM UTC
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports in github.com/coredns/coredns
v0.9.9 - v1.14.2
v0.9.9 - v1.14.2
Summary
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports in github.com/coredns/coredns
Details
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports in github.com/coredns/coredns
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
3 hours ago
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP in github.com/coredns/coredns
v0.9.9 - v1.14.6 GO-2026-6506
v0.9.9 - v1.14.6 GO-2026-6506
Unknown
3 hours ago
CoreDNS: Unauthenticated memory exhaustion in custom transports in github.com/coredns/coredns
v0.9.9 - v1.14.6 GO-2026-6507
v0.9.9 - v1.14.6 GO-2026-6507
High Risk
10 days ago
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
v0.9.9 - v1.14.6 GHSA-9gm5-9rfh-m6vx
v0.9.9 - v1.14.6 GHSA-9gm5-9rfh-m6vx
High Risk
10 days ago
CoreDNS: Unauthenticated memory exhaustion in custom transports
v0.9.9 - v1.14.6 GHSA-mrg3-qvqr-jw29
v0.9.9 - v1.14.6 GHSA-mrg3-qvqr-jw29
Unknown
3 months ago
CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC in github.com/coredns/coredns
v0.9.9 - v1.14.2 GO-2026-5583
v0.9.9 - v1.14.2 GO-2026-5583
Impacted packages
Timeline
Published
3 months ago
June 25, 2026 at 10:34 PM UTC
Last Modified
3 months ago
June 25, 2026 at 11:01 PM UTC