CVE-2026-26017

medium

Description

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.

References

https://github.com/coredns/coredns/security/advisories/GHSA-c9v3-4pv7-87pr

https://github.com/coredns/coredns/releases/tag/v1.14.2

Details

Source: Mitre, NVD

Published: 2026-03-06

Updated: 2026-03-09

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00041