Bug 2535596 (CVE-2026-86003)
| Summary: | CVE-2026-86003 github.com/coredns/coredns: CoreDNS: Unauthorized DNS record modification via unvalidated DNS updates | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akhatavk, aos-team-art-private, asdas, dpaolell, gparvin, jbalunas, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhaigner, sghai, sidsharm, suppawar, tsze, vlaad |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in CoreDNS. The DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners do not properly validate incoming DNS update requests. An unauthenticated client can send a specially crafted DNS update (RFC 2136 UPDATE) that CoreDNS forwards to an upstream DNS server. If the upstream server trusts CoreDNS, this can lead to unauthorized modification, addition, or deletion of DNS records, potentially redirecting traffic or disrupting the DNS zone.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-16 18:51:29 UTC
|