<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:25:33.402685+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12012</id>
    <title>bdu:2026-12012</title>
    <updated>2026-10-04T02:25:33.574297+00:00</updated>
    <content>bdu:2026-12012</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0299</id>
    <title>certfr-2026-avi-0299 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-04T02:25:33.574335+00:00</updated>
    <content>certfr-2026-avi-0299</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0299"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bb57522</id>
    <title>Withdrawn: CLEANSTART-2026-BB57522 — Security fixes in kubernetes-dns-node-cache 1.25.0-r8</title>
    <updated>2026-10-04T02:25:33.574362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kubernetes-dns-node-cache</p>
<p>Package kubernetes-dns-node-cache version 1.25.0-r8 fixes 17 vulnerabilities: CVE-2026-41178, CVE-2026-35579, CVE-2026-46600, CVE-2025-64702, CVE-2025-68151...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bb57522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337446</id>
    <title>EUVD-2026-337446</title>
    <updated>2026-10-04T02:25:33.574393+00:00</updated>
    <content>EUVD-2026-337446</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337446"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26018</id>
    <title>fkie_cve-2026-26018</title>
    <updated>2026-10-04T02:25:33.574405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-26018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h75p-j8xm-m278</id>
    <title>GHSA-h75p-j8xm-m278 — CoreDNS Loop Detection Denial of Service Vulnerability</title>
    <updated>2026-10-04T02:25:33.574429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/coredns/coredns</p>
<p>## Executive Summary</p>
<p>A Denial of Service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process.</p>
<p>---
## Technical Details</p>
<p>### Vulnerability Description</p>
<p>The CoreDNS `loop` plugin is designed to detect forwarding loops by performing a self-test during server startup. The plugin generates a random query name (`qname`) using Go's `math/rand` package and sends an HINFO query to itself. If the server receives multiple matching queries, it assumes a forwarding loop exists and terminates.</p>
<p>**The vulnerability arises from two design flaws:**</p>
<p>1. **Predictable PRNG Seed**: The random number generator is seeded with `time.Now().UnixNano()`, making the generated qname predictable if an attacker knows the approximate server start time.</p>
<p>2. **Fatal Error Handler**: When the plugin detects what it believes is a loop (3+ matching HINFO queries), it calls `log.Fatalf()` which invokes `os.Exit(1)`, immediately terminating the process without cleanup or recovery.</p>
<p>### Affected Code</p>
<p>**File: `plugin/loop/setup.go`**
```go
// PRNG seeded with predictable timestamp
var r = rand.New(time.Now().UnixNano())</p>
<p>// Qname generation using two consecutive PRNG calls
func qname(zone string) string {
    l1 := strconv.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h75p-j8xm-m278"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-26018</id>
    <title>msrc_CVE-2026-26018 — CoreDNS Loop Detection Denial of Service Vulnerability</title>
    <updated>2026-10-04T02:25:33.574487+00:00</updated>
    <content>msrc_CVE-2026-26018</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-26018"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3184</id>
    <title>OESA-2026-3184 — coredns security update</title>
    <updated>2026-10-04T02:25:33.574504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP4: coredns, openEuler:20.03-LTS-SP4: coredns, openEuler:22.03-LTS-SP4: coredns, openEuler:24.03-LTS-SP1: coredns, openEuler:24.03-LTS-SP3: coredns</p>
<p>CoreDNS is a fast and flexible DNS server. The key word here is flexible: with CoreDNS you are able to do what you want with your DNS data by utilizing plugins.

Security Fix(es):</p>
<p>CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS&amp;apos;s loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.(CVE-2026-26018)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10297-1</id>
    <title>openSUSE-SU-2026:10297-1 — coredns-1.14.2-1.1 on GA media</title>
    <updated>2026-10-04T02:25:33.574534+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>coredns-1.14.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10297-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:25127</id>
    <title>RHSA-2026:25127 — Red Hat Security Advisory: Submariner v0.21 security fixes and container updates</title>
    <updated>2026-10-04T02:25:33.574551+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>github.com/containerd/containerd: containerd local privilege escalation golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) net/url: Incorrect parsing of IPv6 host literals in net/url github.com/coredns/coredns: CoreDNS: DNS access control bypass due to plugin execution order flaw github.com/coredns/coredns: CoreDNS: Denial of Service vulnerability due to predictable pseudo-random number generation crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/coredns/coredns: CoreDNS: Denial of Service via oversized DNS-over-HTTPS GET requests google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object github.com/coredns/coredns: CoreDNS: Authentication bypass allows unauthorized access to TSIG-protected functionalities</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:25127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0627</id>
    <title>WID-SEC-W-2026-0627 — CoreDNS: Mehrere Schwachstellen</title>
    <updated>2026-10-04T02:25:33.574589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in CoreDNS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0627"/>
  </entry>
</feed>
