<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:08:27.258592+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03630</id>
    <title>bdu:2026-03630</title>
    <updated>2026-10-03T06:08:27.274086+00:00</updated>
    <content>bdu:2026-03630</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0339</id>
    <title>certfr-2026-avi-0339 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T06:08:27.274126+00:00</updated>
    <content>certfr-2026-avi-0339</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bb57522</id>
    <title>Withdrawn: CLEANSTART-2026-BB57522 — Security fixes in kubernetes-dns-node-cache 1.25.0-r8</title>
    <updated>2026-10-03T06:08:27.274145+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kubernetes-dns-node-cache</p>
<p>Package kubernetes-dns-node-cache version 1.25.0-r8 fixes 17 vulnerabilities: CVE-2026-41178, CVE-2026-35579, CVE-2026-46600, CVE-2025-64702, CVE-2025-68151...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bb57522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265172</id>
    <title>EUVD-2026-265172</title>
    <updated>2026-10-03T06:08:27.274176+00:00</updated>
    <content>EUVD-2026-265172</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68151</id>
    <title>fkie_cve-2025-68151</title>
    <updated>2026-10-03T06:08:27.274189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical resource-limiting controls. An unauthenticated remote attacker can exhaust memory and degrade or crash the server by opening many concurrent connections, streams, or sending oversized request bodies. The issue is similar in nature to CVE-2025-47950 (QUIC DoS) but affects additional server types that do not enforce connection limits, stream limits, or message size constraints. Version 1.14.0 contains a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-68151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-527x-5wrf-22m2</id>
    <title>GHSA-527x-5wrf-22m2 — CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages</title>
    <updated>2026-10-03T06:08:27.274212+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/coredns/coredns</p>
<p>Multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical resource-limiting controls. An unauthenticated remote attacker can exhaust memory and degrade or crash the server by opening many concurrent connections, streams, or sending oversized request bodies. The issue is similar in nature to CVE-2025-47950 (QUIC DoS) but affects additional server types that do not enforce connection limits, stream limits, or message size constraints.</p>
<p>### Impact</p>
<p>#### 1. Missing connection and stream limits (gRPC / HTTPS / HTTP3)</p>
<p>The affected servers do not enforce reasonable upper bounds on concurrent connections or active streams. An attacker can:</p>
<p>- Open many parallel connections
- Rapidly issue requests without limit
- Consume memory until the CoreDNS process becomes unresponsive or is terminated by the OOM killer</p>
<p>Testing demonstrates that modest resource configurations (e.g., 256 MB RAM) can be exhausted quickly. Increasing concurrency parameters in the PoCs allows attackers to scale the impact.</p>
<p>#### 2. Missing message-size validation in the gRPC server</p>
<p>The gRPC server accepts arbitrarily large protobuf messages (default limit ~4 MB per request) without validating against DNS protocol constraints (maximum 64 KB). Sending multiple concurrent oversized messages can quickly exhaust available memory.</p>
<p>This vulnerability mirrors earlier hardening work in PR https://github.com/coredns/coredns/pull/7490, which applied checks for upstream proxying but left server-side r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-527x-5wrf-22m2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-68151</id>
    <title>msrc_CVE-2025-68151 — CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages</title>
    <updated>2026-10-03T06:08:27.274251+00:00</updated>
    <content>msrc_CVE-2025-68151</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-68151"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3062</id>
    <title>OESA-2026-3062 — coredns security update</title>
    <updated>2026-10-03T06:08:27.274267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP4: coredns</p>
<p>CoreDNS is a fast and flexible DNS server. The key word here is flexible: with CoreDNS you are able to do what you want with your DNS data by utilizing plugins.

Security Fix(es):</p>
<p>CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical resource-limiting controls. An unauthenticated remote attacker can exhaust memory and degrade or crash the server by opening many concurrent connections, streams, or sending oversized request bodies. The issue is similar in nature to CVE-2025-47950 (QUIC DoS) but affects additional server types that do not enforce connection limits, stream limits, or message size constraints. Version 1.14.0 contains a patch.(CVE-2025-68151)</p>
<p>CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.(CVE-2026-26017)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:25127</id>
    <title>RHSA-2026:25127 — Red Hat Security Advisory: Submariner v0.21 security fixes and container updates</title>
    <updated>2026-10-03T06:08:27.274294+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/containerd/containerd: containerd local privilege escalation golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) net/url: Incorrect parsing of IPv6 host literals in net/url github.com/coredns/coredns: CoreDNS: DNS access control bypass due to plugin execution order flaw github.com/coredns/coredns: CoreDNS: Denial of Service vulnerability due to predictable pseudo-random number generation crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/coredns/coredns: CoreDNS: Denial of Service via oversized DNS-over-HTTPS GET requests google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object github.com/coredns/coredns: CoreDNS: Authentication bypass allows unauthorized access to TSIG-protected functionalities</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:25127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0047</id>
    <title>WID-SEC-W-2026-0047 — CoreDNS: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T06:08:27.274329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in CoreDNS ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0047"/>
  </entry>
</feed>
